ThreatCluster

737 Fake Chrome VPN Extensions Redirect Browser Traffic to Attackers

First seen 12 Aug 2026, 14:07 UTC GbhackersCybersecuritynews 83% similarity 66

Article Content

Browse articles
ThreatCluster

A large-scale operation involving 737 fake Chrome VPN extensions has been uncovered, redirecting browser traffic through SOCKS5 proxy servers controlled by attackers. These extensions, advertised as free VPN tools, were published under at least 40 developer accounts, with 274 impersonating recognized VPN brands. The operation has garnered over 75,486 installs, with 516 extensions remaining active at the time of the report. This incident raises significant concerns about user privacy and security, as unsuspecting users may have unknowingly compromised their data. Researchers are continuing to investigate the full extent of the operation and its implications for users. Immediate action is recommended to remove these extensions and secure affected systems.

Key Points: • 737 fake Chrome VPN extensions were found redirecting user traffic to attacker-controlled proxies. • The operation involved at least 40 developer accounts and impersonated 66 recognized VPN brands. • Over 75,486 installs were recorded, with 516 extensions still active at the time of discovery.

ThreatCluster AI How this analysis works

Timeline

2026-08-12
Discovery of fake VPN extensions
Researchers identified 737 fake Chrome extensions hijacking browser traffic through SOCKS5 proxies controlled by attackers.
Cybersecuritynews
2026-08-12
Details of the operation revealed
The operation involved at least 40 developer accounts, with 274 extensions masquerading as recognized brands.
Gbhackers

Community

Browse all →

Tracked Entities in This Story