ALERT! Fake VPN tools are redirecting your browser traffic through unknown proxy servers!
31 suspicious VPN tools have been identified as offered as a VPN for the Google Chrome browser. These VPN tools can secretly redirect users' internet activities through unknown proxy servers.
According to information announced on September 19, 2026, these VPN tools have been installed approximately 356 thousand times. Some of them are offered as "VPN" tools that allow access to popular services such as RuTracker, YouTube, Telegram, Instagram, ChatGPT, Claude, Netflix, Gemini, Discord, Spotify, and LinkedIn, or access to limited resources.
Experts have determined that although users consider these VPN tools as a simple VPN tool, they have the ability to change the browser's proxy settings and route internet traffic through unknown servers.
One of the most installed extensions is RuTracker VPN, with an installation count of approximately 200 thousand.
How do fake VPNs work?
One of the main functions of a regular VPN service is to route the connection between the user's device and internet resources through a VPN server. Therefore, it is important to pay special attention to the permissions granted when installing a VPN application or extension.
The identified suspicious extensions use a proxy permission to control the browser's proxy settings.
According to Chrome documentation, this permission allows the extension to control the browser's proxy configuration. For example, it can route traffic through a specific proxy server or specify which connection should be made directly using a PAC (Proxy Auto-Configuration) script.
In this case, this capability has been used in a way that is not sufficiently transparent for the user.
The attack mechanism can be visualized as follows:
User → Chrome → Fake VPN extension → Unknown proxy server → Website on the internet
Regardless of which website the user is visiting, the extension can route some or all connections through the proxy server it requires.
The most dangerous aspect is that the list of proxy servers can be changed later.
One of the dangers of this campaign is that the addresses of the proxy servers are not permanently stored within the extension itself.
Instead, the configuration data is downloaded from external sources.
Investigators have found that configuration-related information is stored in various sources such as GitHub Pages, Blogspot, Google documents, and Telegram channels.
This creates great convenience for attackers. Because they can change:
- which websites are opened through the proxy;
- which proxy servers are used;
- which infrastructure the traffic is directed to, without updating the extension.
In other words, after a user installs an extension once, its operating mechanism can be changed remotely later.
What is PAC script and why is it dangerous?
PAC (Proxy Auto-Configuration) is a configuration script that tells the browser which proxy to use for a connection or whether to connect directly to a specific internet address.
Chrome official documentation shows that the `pac_script` mode specifies the proxy configuration through a PAC script.
Therefore, the user might think that a simple "VPN extension" tool actually affects the browser's network connections.
Especially if the extension demands the right to access all URLs and can change proxy settings at the same time, extreme caution is required.
The "Total VPN" option redirects even more traffic.
Among the identified extensions, the option named "Total VPN" is noted as posing an additional risk.
While other extensions are designed to route traffic related to specific services or websites through a proxy, this option is capable of routing all browser traffic through a proxy.
This significantly increases the risk.
Because the traffic can pass through unknown infrastructure not only when the user is accessing a single service but also when they are working with:
- email;
- social networks;
- messenger web versions;
- work platforms;
- cloud services;
- other personal and corporate resources.
Does HTTPS provide full protection?
Here, it is important to understand a crucial point.
Routing traffic through a proxy does not automatically cancel HTTPS encryption. If HTTPS is present, the content of the web page usually remains encrypted.
However, an unknown proxy operator can monitor:
- which servers the user is connecting to;
- the connection time and volume;
- some technical connection details.
In simple HTTP connections, the risk of seeing or altering data is even higher.
Furthermore, using an unknown proxy infrastructure can expose the user to risks of redirection, blocking, or involvement in additional malicious activities.
Therefore, the approach of "if there is HTTPS, there is no danger" is not correct.
How are the extensions hidden?
Investigators have found that some configuration data within the extensions is encoded using simple encoding/obfuscation methods like Base64 and Caesar shift.
This is not strong encryption. Such methods are used mainly to hide data from simple inspection or to make code analysis slightly more complicated.
In the decoded data, information about general authentication details for connecting to proxy servers and service usage durations were identified.
Furthermore, it was noted that the paid VIP version of the proxy service is available in the investigation.
This situation suggests that this infrastructure is not just random malicious code, but a system aimed at commercializing the management of user traffic and the use of the proxy service.
Why are the permissions granted to the Chrome extension important?
Chrome extensions use special permissions to perform various tasks. For example, the proxy permission allows the extension to control the browser's proxy settings. webRequest grants the extension permissions to monitor network requests and in some cases, to modify or block them.
Therefore, it is dangerous to judge based only on the name or the number of users when installing an extension.
For example:
Why does an extension named "VPN" demand the right to access all websites and browser proxy settings?
should be asked.
If there is a mismatch between the extension's main function and the permissions granted to it, it is considered a serious warning sign.
What should users do?
If a user has installed one of the suspicious VPN extensions mentioned above, the following measures are recommended:
1. Immediately disable the suspicious extension
Check the list of extensions in the Chrome browser and remove VPN extensions installed from unused or untrusted sources.
2. Check browser proxy settings
Even after disabling the extension, check that there are no unknown proxy settings remaining in the browser or operating system.
3. Update important account passwords
If the suspicious extension was installed while using email, social media, banking, corporate, or other important accounts, it is recommended to update passwords as a precaution.
4. Check active sessions
Review open sessions on important services and terminate any unknown devices or sessions.
5. Enable two-factor authentication
Enabling 2FA/MFA for important accounts reduces the risk of access via password alone.
6. Regularly check browser extensions
It is also appropriate to review extensions that have been installed on the computer for a long time and are not currently in use.
Recommendations for Organizations
Browser extensions should be under separate control in organizations. Especially if employees can install any Chrome extension independently on their work computers, this poses an additional risk.
IT and Cybersecurity departments:
- Restrict the installation of unauthorized Chrome extensions;
- Inventory extensions with high permissions;
- Control permissions such as proxy, webRequest, and access to all URLs separately; use extension policies on managed devices;
- monitor traffic going to suspicious external domains;
- audit extensions installed by users regularly.
Chrome's official documentation also indicates that granting only necessary permissions to extensions and not excessive rights is reasonable from a security perspective.
Identified Technical Indicators
The following sources related to this infrastructure were noted in the investigation:
s-extension.github.io
dtxtension.blogspot.com
t.me/liservers
api.hhos.ru
mainapi
Furthermore, SHA-256 hashes of some extensions' archived CRX files were also identified.
It is recommended to check these indicators in SIEM, EDR/XDR, DNS, proxy, and network monitoring tools in the organization's cybersecurity departments.
This should be considered as a basis for further investigation, rather than proving that the device is compromised by the indicators themselves.
This situation once again shows how much impact a seemingly ordinary browser extension can have on a user's online activities.
When a user installs an extension named "VPN," they might be installing a third-party application that has the ability to control the browser's network settings, not just the ability to access a blocked website.
Especially if the extension demands the right to access all URLs, the ability to control proxy settings, and can download a list of proxy servers from an external source, extreme caution is necessary towards such tools.
The most important rule: Do not consider a VPN extension trustworthy based only on its name, rating, or number of installations. The developer, the permissions it demands, and where it routes traffic must also be checked.
Furthermore, if VPN service is necessary, it is more appropriate to use a trusted and official application rather than unknown browser extensions.
