737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One
Read original article ↗AI Summary
A large-scale campaign involving 737 malicious Chrome VPN and proxy extensions has been uncovered, primarily targeting Russian-speaking users. These extensions impersonate 66 legitimate VPN brands and route users' entire browser traffic through SOCKS5 proxies controlled by a single threat actor, enabling adversary-in-the-middle (AitM) monitoring of destinations, IP addresses, SNI values, and unencrypted HTTP traffic. The extensions bypass Chrome Web Store policies by submitting false claims, using code obfuscation, and performing post-approval code substitution to hide malicious behavior, including non-existent premium tiers and affiliate monetization schemes.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.