Researchers found 737 Chrome VPN/proxy extensions that impersonated well-known privacy brands and routed users’ browser traffic through attacker-controlled SOCKS5 proxies. The activity mainly targeted Russian-speaking users trying to access blocked services, putting the operator in a position to observe browsing destinations and other metadata. Google removed some extensions, but many were still active at the time of reporting.
Key findings
- 737 free VPN/proxy extensions were found “mainly target[ing] Russian-speaking users seeking access to blocked services.”
- 274 extensions “impersonate 66 established VPN and privacy brands,” including Proton VPN, NordVPN, Surfshark, and others.
- Researchers observed that “520 of the 522 in the bulk corpus route browser traffic through the same SOCKS5 infrastructure.”
- Extensions set Chrome proxy settings to “a fixed SOCKS5 server on port 1082,” placing the operator in an adversary-in-the-middle position.
- Some extensions used fake UX and store-review deception, including identical claims like “No data transmitted to external servers” and “No user tracking or logging.”
- 221 extensions were removed, while “the remaining 516 extensions have been listed as active.”
Who’s being targeted
- Commonly targeted roles: All employees, IT / Helpdesk, Security awareness, Procurement / IT asset management (software approvals), Browser management / Endpoint management teams.
- Affected industries: Any organization with Chrome users, Consumer internet users, Media and information access users in censored regions.
- Attack channels: website.
- Impersonated: Well-known VPN/privacy brands (e.g., Proton VPN, NordVPN, Surfshark), A VPN/proxy extension posing as a legitimate privacy tool.
Awareness takeaways
- Only install browser extensions from verified publishers, and treat brand look-alikes as suspicious.
- Be cautious of ‘free VPN’ tools: they can route all browsing through third-party infrastructure that can observe where you’re going online.
- Watch for product claims that don’t match reality (fake premium tiers/locations or fake connection indicators).
- Assume an extension can change after approval; updates can introduce new behavior, so monitor and re-review extensions over time.
Red flags to watch for
- Impersonates a known brand rather than being published by the official vendor
- Promises paid tiers or premium locations that do not exist
- Routes all traffic through a fixed proxy (not a transparent, vendor-managed VPN)
- Fake or misleading interface/connection status
- Only bypasses localhost/127.0.0.1 while funneling everything else through a proxy
- Adds new remote configuration after approval (behavior changes over time)
Read the video transcript
That “free Chrome VPN” you just installed? It might be sending every site you visit through someone else’s server. Researchers found 737 Chrome VPN and proxy extensions, many in Russian, impersonating brands like Proton VPN, NordVPN, and Surfshark. Behind the scenes they set Chrome to use a fixed SOCKS5 proxy on port 1082, so one provider sits in the middle of your entire browser session. The trick: a slick fake interface. The extension shows a nice connect animation and status “Connected”, but tests show every VPN connection fails while your real browsing still goes through their proxy. Many even promise fake premium locations that don’t exist. Your move: if you use a VPN in Chrome, open the extension’s page and check the publisher. If it’s not the official vendor, remove it now, don’t let a fake VPN sit in the middle of your browsing.