
More than 737 browser extensions published on the Chrome Web Store impersonated well-known VPN and proxy services while routing users’ traffic through SOCKS5 proxies operated by a single provider.
Some of the extensions impersonated dozens of established brands, including Proton VPN, NordVPN, Surfshark, ExpressVPN, and Cloudflare’s 1.1.1.1 public domain name system (DNS) resolver.
Researchers at application security company Socket found that the campaign relied on 40 publisher accounts and used a shared analytics account.
While on the Chrome Web Store, the extensions were downloaded nearly 75,000 times, mainly by Russian users looking for tools to bypass blocked services in the country.
“With all browser traffic forced through it [the relay], the threat actor’s server is positioned to read every destination, every TLS SNI value, the victim’s source IP, and any request body sent over plain HTTP,” Socket explains.
The researchers identified three threat behaviors associated with the campaign:
Socket could not analyze the code in all of the extensions because 212 of them had already been removed when the researchers collected them.
Based on the strings found, the campaign appears to be an attempt to funnel customers to a subscription-based VPN service in Russia.
The researchers noted that the mechanism used by the extensions appears no different from that of a legitimate service, but they identified several indicators of intentional deception:
Socket says that while Google removed more than 200 of the extensions related to the identified campaign, over 500 of them are still available in Chrome’s Web Store.
Socket has published the IDs of all extensions linked to the campaign and recommends that users check their browsers for any of them and remove them if found. They should also confirm that Chrome’s proxy configuration is back to normal.
#chrome #extensions #fake #hundreds #news #proxy #route #through #traffic #vpn — News
© Bulletproof Servers. All rights reserved.