More than 737 browser extensions published on the Chrome Web Store were found impersonating popular VPN and proxy services while routing users’ internet traffic through SOCKS5 proxies operated by a single provider.

Researchers at application security company Socket discovered that the extensions copied the names and identities of well-known services, including Proton VPN, NordVPN, Surfshark, ExpressVPN and Cloudflare’s 1.1.1.1 DNS resolver. Some of the extensions were used to impersonate multiple established brands.

The campaign relied on 40 publisher accounts and a shared analytics account, according to Socket. The extensions were downloaded nearly 75,000 times from the Chrome Web Store, with most of the users reportedly located in Russia and looking for ways to access services blocked in the country.

The extensions could force browser traffic through the operators’ SOCKS5 proxy servers. Socket said this placed the operators in a position to see information such as the websites users were connecting to, their TLS SNI values, source IP addresses and any request data sent over unencrypted HTTP connections.

Researchers identified several behaviors across the extensions. A total of 520 extensions were configured to route all browser traffic through the operators’ SOCKS5 proxies on port 1082. Another 104 extensions used Cloudflare or Google DNS-over-HTTPS to resolve proxy hostnames, making the proxy infrastructure more difficult to identify and analyze.

Some extensions also advertised premium VPN servers in countries including Japan, Singapore, Canada, Australia and Turkey even though those servers did not exist. Socket said this appeared to be connected to an attempt to direct users toward a subscription-based VPN service in Russia.

READ
Cloudflare Blocks 800+ DDoS Attacks Exceeding 1 Tbps in Q2

Socket was unable to analyze the code of all 737 extensions because 212 had already been removed by the time researchers collected the samples. However, the researchers found several signs that the campaign involved intentional deception rather than simply poorly developed VPN extensions.

These included impersonating established VPN brands, advertising nonexistent premium server locations, using payment or connection mechanisms that did not work, providing misleading information to Chrome Web Store reviewers, adding remote configuration after approval and using techniques designed to hide proxy destinations from analysis.

Although the extensions used mechanisms found in legitimate VPN services, Socket said the combination of these behaviors indicated the extensions were designed to deceive users and redirect their traffic through the campaign’s proxy infrastructure.

Google has removed more than 200 extensions linked to the campaign, but Socket said more than 500 were still available on the Chrome Web Store when the researchers reported their findings.


Buy ExpressVPN with PayPal or Credit Card

Socket has published the IDs of the extensions associated with the campaign and recommends that users check their Chrome installations for any of them and remove them if found. Users should also verify that Chrome’s proxy settings have returned to their normal configuration.

Advertisement