A large collection of 737 free virtual private network (VPN) and proxy tools has been discovered, primarily targeting Russian speakers who are looking for blocked service access. Among those identified, 274 have been confirmed to impersonate 66 well-known VPN and privacy brands, including ProtonVPN, NordVPN, Surfshark, AdGuard VPN, Browsec, ExpressVPN, CyberGhost, Windscribe, TunnelBear, Cloudflare's 1.1.1.1, and Google's Outline. Censorship circumvention extensions route users' entire browser sessions through SOCKS5 proxies operated by a single provider, as security researcher Kush Pandya revealed.

All these extensions configure their proxy settings to point to a fixed SOCKS5 server on port 1082, placing threat actors in an adversary-in-the-middle (AitM) position for monitoring browser destinations, source IP addresses, TLS SNI values, and plain HTTP request bodies.

The threat actor is operating a subscription-based VPN business in Russia, as evidenced by a 12-digit taxpayer ID and the leakage of Windows build paths ("C:\Users\ollob\OneDrive\Документы\1.myxa-work\08.06.26\\\-release.zip"). Shipped an internal manual titled "Промт для сотрудников" (translated to "Prompt for employees") instructing users not to directly input the domain into "chrome.proxy.settings" but instead provide only the resolved IP. Attempts to game the Chrome Web Store review process by submitting identical justifications, stating "No data transmitted to external servers" or "No user tracking or logging."

A Chrome extension previously removed for Prompt Poaching tactics has resurfaced with a new monetization strategy.