A vast network of fake Chrome VPN extensions has been discovered, masquerading as reputable brands like ProtonVPN and NordVPN. The Threat Research Team identified 737 free VPN and proxy extensions linked to at least 40 Chrome Web Store developer accounts. The campaign had amassed 75,486 displayed installs, with 516 remaining live with 58,318 installs at the time of collection.
This operation primarily targets Russian-speaking users seeking access to blocked services like Instagram, ChatGPT, and YouTube. Of the 522 packages collected in bulk, 520 configured Chrome to send browser traffic through the same SOCKS5 infrastructure on port 1082.
This configuration places the proxy operator in an adversary-in-the-middle position, allowing them to intercept and observe websites visited by victims, TLS SNI metadata, source IP addresses, and any data transmitted over unencrypted HTTP. The primary concern lies in potential deception: brand impersonation, hidden infrastructure, fake premium offerings, and misleading store disclosures. This document was filled in with project details as "skyproxy.space."
It instructed employees on using DNS-over-HTTPS services from Cloudflare or Google for resolving proxy hostnames. This method prevents victims' devices from making plaintext DNS requests and complicates domain-based blocking or investigation efforts. The campaign also employed remote configuration in 66 extensions by following HTTP redirects to discover current infrastructure and download settings dynamically at runtime.












