Feed›Network & Infrastructure›737 Chrome VPN extensions impersonate brands to hijack brows...
Network & InfrastructureCyber Insider
8.0 — CRITICAL

737 Chrome VPN extensions impersonate brands to hijack browser traffic

📅 12 August 2026 at 14:21 UTC📰 Cyber InsiderView original source ↗
737 Chrome VPN extensions impersonate brands to hijack browser traffic

Socket researchers have uncovered a sprawling network of 737 Chrome VPN extensions that impersonated legitimate privacy brands, redirected browser traffic through shared SOCKS5 infrastructure, and accumulated more than 75,000 installs. The campaign primarily targeted Russian-speaking users looking for ways to access blocked services such as Instagram, YouTube, and ChatGPT. Socket’s Threat Research Team identified extensions … The post 737 Chrome VPN extensions impersonate brands to hijack browser traffic appeared first on CyberInsider.

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

A network of 737 Chrome VPN extensions impersonated legitimate brands, redirected browser traffic through shared SOCKS5 infrastructure, and accumulated over 75,000 installs primarily targeting Russian-speaking users.

⚙️Technical Details
Affected Systems
Chrome Web Store developer accountsChrome VPN extensions
Attack Vectors
Impersonation of legitimate brandsRedirecting browser traffic through SOCKS5 infrastructureUse of shared proxy servers and DNS-over-HTTPS services
💥Impact Assessment
Severity: high
Who Is at Risk
Russian-speaking users who installed the affected Chrome VPN extensions
🛡️Recommended Actions
1Users should remove the affected Chrome VPN extension
2Verify that Chrome's proxy configuration has returned to normal
3Change credentials submitted through non-HTTPS websites while the extension was active
📦Affected Products
Chrome Web Store developer accountsChrome VPN extensions

Read the full article

This is a curated summary. The complete article is available at Cyber Insider.

Read on Cyber Insider ↗
← Back to feed