Malicious VPN and proxy extension campaign targeting Russian-speaking users
Campaign
Summary
Hide ▲
Show ▼
A 737-extension campaign is intercepting browser traffic for Russian-speaking users by routing sessions through SOCKS5 proxy infrastructure, exposing destinations, source IPs, and TLS SNI values. The operation spans at least 40 Chrome Web Store developer accounts and impersonates 66 VPN and privacy brands, including Proton VPN, NordVPN, Surfshark, and ExpressVPN. The scale of installation activity and the large number of still-active add-ons indicate the operation remains ongoing.
Related Happenings
Lurking Lizard trojanized 7-Zip installer campaign
Campaign
H score84
First: 09.07.2026 07:01
Last: 09.07.2026 07:01
Sources 1
About this happening:
A Lurking Lizard campaign used a trojanized 7-Zip installer to recruit devices as proxy nodes, expanding a residential-proxy operation that has run since at least Au...
Lurking Lizard trojanized 7-Zip installer campaign
CampaignAbout this happening: A Lurking Lizard campaign used a trojanized 7-Zip installer to recruit devices as proxy nodes, expanding a residential-proxy operation that has run since at least Au...
Lurking Lizard ecosystem shift changes threat-actor operations
Threat Actor Meta
H score87
First: 09.07.2026 07:01
Last: 09.07.2026 07:01
Sources 1
About this happening:
The Lurking Lizard operation has been exposed as a multi-stage residential proxy business, turning compromised devices into monetizable proxy nodes and widening unauthoriz...
Lurking Lizard ecosystem shift changes threat-actor operations
Threat Actor MetaAbout this happening: The Lurking Lizard operation has been exposed as a multi-stage residential proxy business, turning compromised devices into monetizable proxy nodes and widening unauthoriz...
Vo1d botnet campaign targeting unofficial Android-based TV boxes
Campaign
H score88
First: 18.06.2026 20:37
Last: 18.06.2026 20:37
Sources 1
About this happening:
NetNut used the Popa botnet and deceptive SDKs on off-brand Android-based smart TVs, streaming media boxes, and unofficial apps to turn home connections into residen...
Vo1d botnet campaign targeting unofficial Android-based TV boxes
CampaignAbout this happening: NetNut used the Popa botnet and deceptive SDKs on off-brand Android-based smart TVs, streaming media boxes, and unofficial apps to turn home connections into residen...
Latest development: 03.07.2026 12:35
Google disabled all Google accounts used by NetNut for malware command-and-control, updated Google Play Protect to warn Android users, and disabled apps containing the compromised SDKs. The FBI’s seizure banner appeared on netnut.com while netnut.io briefly remained accessible, and Google said the coordinated actions caused significant degradation to NetNut’s proxy network and business operations.
GREYVIBE's Kremlin-aligned role in the Russian cybercrime ecosystem
Threat Actor Meta
H score15
First: 29.05.2026 14:31
Last: 29.05.2026 14:31
Sources 1
About this happening:
A newly characterized GREYVIBE actor sits in a grey zone between Kremlin-aligned intelligence work and the Russian cybercrime ecosystem, complicating attribution f...
GREYVIBE's Kremlin-aligned role in the Russian cybercrime ecosystem
Threat Actor MetaAbout this happening: A newly characterized GREYVIBE actor sits in a grey zone between Kremlin-aligned intelligence work and the Russian cybercrime ecosystem, complicating attribution f...
GreyVibe AI-assisted cyberespionage campaign targeting Ukraine-linked organizations
Campaign
H score39
First: 29.05.2026 01:24
Last: 29.05.2026 01:24
Sources 1
About this happening:
GreyVibe is running an AI-assisted cyberespionage campaign against Ukrainian and Ukraine-related organizations, expanding the threat to military, government, civilian,...
GreyVibe AI-assisted cyberespionage campaign targeting Ukraine-linked organizations
CampaignAbout this happening: GreyVibe is running an AI-assisted cyberespionage campaign against Ukrainian and Ukraine-related organizations, expanding the threat to military, government, civilian,...
Timeline
-
12.08.2026 17:09 2 articles · 2h ago
737 Chrome VPN and proxy extensions intercept browser traffic through SOCKS5 relays
Initial DisclosureResearchers found 737 free VPN and proxy extensions spread across at least 40 Chrome Web Store developer accounts that targeted Russian-speaking users seeking access to blocked services, impersonated 66 VPN and privacy brands, and routed browser sessions through a fixed SOCKS5 server on port 1082. The extensions placed the operator in an adversary-in-the-middle position to observe browser destinations, source IP addresses, TLS SNI values, and plain-HTTP request bodies, while 221 add-ons were removed from the Chrome Web Store and 516 remained active. Researchers also said the operator appears to run a subscription VPN business in Russia, based on a 12-digit taxpayer number and leaked Windows build paths.
Show sources
- 737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One — thehackernews.com — 12.08.2026 17:09
- 737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One — thehackernews.com — 12.08.2026 17:09