Socket’s Threat Research Team uncovered a campaign of 737 free VPN and proxy Chrome extensions spread across at least 40 developer accounts, many of which impersonate established brands and route browser traffic through a single operator’s SOCKS5 infrastructure. The operation also includes fake premium servers, DNS-over-HTTPS evasion, post-approval code substitution, and coordinated store-review deception tied to Myxa VPN and related domains. #MyxaVPN #ChromeWebStore #AmneziaVPN #AntiZapret
Keypoints
- Socket identified 737 VPN and proxy extensions across at least 40 Chrome Web Store developer accounts.
- 274 extensions impersonate 66 established VPN and privacy brands, including AmneziaVPN, AntiZapret, Proton VPN, NordVPN, Surfshark, AdGuard VPN, and Cloudflare’s 1.1.1.1.
- 520 of 522 retrieved extensions route all browser traffic through a fixed SOCKS5 proxy, creating an adversary-in-the-middle position over browser sessions.
- 104 extensions use DNS-over-HTTPS to resolve their own proxy hostnames and avoid plaintext DNS queries for the operator’s domains.
- The campaign advertises premium server locations that do not exist, and some packages contain fake or trivially bypassed license checks.
- Evidence points to deliberate policy evasion, including byte-identical reviewer justifications, post-approval code substitution, and internal instructions to avoid placing domains directly into proxy settings.
- The operator also runs a subscription VPN business in Russia, with related domains, billing infrastructure, and public policy pages tied to the extension estate.
MITRE Techniques
- [T1176.001 ] Browser Extensions – The campaign delivered malicious functionality through Chrome extensions that proxy traffic and manage configuration. [‘Published as Chrome browser extensions’]
- [T1557 ] Adversary-in-the-Middle – The extensions force browser traffic through operator-controlled SOCKS5 nodes, placing the actor between the victim and destinations. [‘placing the threat actor in an adversary-in-the-middle position over all browser traffic’]
- [T1090.002 ] External Proxy – The packages configure a fixed SOCKS5 server to relay all browser traffic through external infrastructure. [‘set chrome.proxy.settings to a fixed SOCKS5 server on port 1082’]
- [T1572 ] Protocol Tunneling – Browser traffic is tunneled through SOCKS5 and, in the paid tier, VLESS-REALITY on port 443. [‘route the user’s entire browser session through SOCKS5 proxies’; ‘VLESS-REALITY on port 443 rather than SOCKS5 on 1082’]
- [T1071.004 ] Application Layer Protocol: DNS – Some extensions use DNS-over-HTTPS to resolve proxy hostnames and avoid plaintext DNS leakage. [‘declare host permissions for Cloudflare and Google DNS-over-HTTPS endpoints’]
- [T1102 ] Web Service – Extensions chase HTTP redirects and fetch remote configuration from live domains at runtime. [‘chase HTTP redirects at runtime to locate whichever threat actor domain is currently live’]
- [T1656 ] Impersonation – Many extensions impersonate known VPN and privacy brands to mislead users. [‘274 of these extensions impersonate 66 established brands’]
- [T1036.005 ] Match Legitimate Name or Location – The campaign uses names and branding that resemble legitimate services and trusted tools. [‘including AmneziaVPN and AntiZapret’]
- [T1204.001 ] User Execution: Malicious Link – The operation opens a Telegram bot link on first install or onboarding to route users outside the extension. [‘Open Telegram bot on first installation’]
- [T1583.001 ] Acquire Infrastructure: Domains – The threat actor registered large numbers of domains for the extension estate and remote configuration. [’21 domains were registered inside a 10-second window’]
- [T1583.003 ] Acquire Infrastructure: Virtual Private Server – The infrastructure includes dedicated hosting and proxy servers used by the campaign. [‘One registrar and one dedicated host’]
- [T1585.002 ] Establish Accounts: Email Accounts – Multiple publisher accounts and related service accounts were used across the operation. [‘published 737 extensions across at least 40 developer accounts’]
- [T1608 ] Stage Capabilities – The actor added remote-configuration layers after approval and shipped staged updates to live extensions. [‘the entire remote-configuration layer was added after approval’]
- [T1027 ] Obfuscated Files or Information – Variable renaming, comments, build-time generation, and split secrets were used to evade detection and static matching. [‘variable names, function names, and comments per build’]
Indicators of Compromise
- [Domains ] Main storefront, landing pages, and campaign domains – myxavpn[.]pro, app[.]myxavpn[.]pro, myxavpn[.]com, myxavpn[.]site, and 4 more domains
- [Domains ] Post-redirect and remote-configuration domains – myxavpn[.]online, myxavpn[.]tech, myxasafe[.]space, and 4 more domains
- [Domains ] Brand-family VPN domains seen across the estate – vpnmyxa[.]site, vpnmyha[.]shop, vpnkomar[.]space, and 2 more domains
- [Domains ] Nameservers and infrastructure domains – ns1[.]reg[.]ru, ns2[.]reg[.]ru, and sverchtun[.]store
- [IP Addresses ] Proxy and hosting infrastructure – 212[.]192[.]14[.]75, 158[.]160[.]228[.]178, and other campaign IPs including 178[.]130[.]47[.]43 and 80[.]92[.]204[.]47
- [File Names ] Extension code and bundled artifacts – worker.js, sw.js, and vpn-bez-limita.zip
- [File Names ] Internal documentation and review assets – config/links.json, PRIVACY_JUSTIFICATIONS.md, and build-info.json
- [Hashes ] Shared justification document fingerprint and signature artifacts – SHA-256 1dea4975f7aaba71bf7821fcf62deca470ef5e21f45c947b103ddeb836ef9b81, and a short ID d67ec5a8fc40ebea
- [Credential / Secret ] Hardcoded token material embedded in code – myxavpn2024secret, and split parts like myxa, vpn, 2024, and secret
- [Browser Extension IDs ] Notable live extension IDs referenced in the article – aaeiefggdeljohngedhpmgidkjcdoebb, aaeiefggdeljohngedhpmgidkjcdoebb, and ofbdlgcpfnhcidmfmddnkkbkejjoffdf
Read more: https://socket.dev/blog/chrome-vpn-extension-impersonation