Find notable cyber news and cases, enriched with sources, timelines, and signals.

Malicious VPN and proxy extension campaign targeting Russian-speaking users

Campaign
First reported
Last updated
Happening score
H score 21
1 unique sources, 1 articles

Summary

Hide ▲

A 737-extension campaign is intercepting browser traffic for Russian-speaking users by routing sessions through SOCKS5 proxy infrastructure, exposing destinations, source IPs, and TLS SNI values. The operation spans at least 40 Chrome Web Store developer accounts and impersonates 66 VPN and privacy brands, including Proton VPN, NordVPN, Surfshark, and ExpressVPN. The scale of installation activity and the large number of still-active add-ons indicate the operation remains ongoing.

Related Happenings

Lurking Lizard trojanized 7-Zip installer campaign

Campaign
H score84 First: 09.07.2026 07:01 Last: 09.07.2026 07:01 Sources 1

About this happening: A Lurking Lizard campaign used a trojanized 7-Zip installer to recruit devices as proxy nodes, expanding a residential-proxy operation that has run since at least Au...

Lurking Lizard ecosystem shift changes threat-actor operations

Threat Actor Meta
H score87 First: 09.07.2026 07:01 Last: 09.07.2026 07:01 Sources 1

About this happening: The Lurking Lizard operation has been exposed as a multi-stage residential proxy business, turning compromised devices into monetizable proxy nodes and widening unauthoriz...

Vo1d botnet campaign targeting unofficial Android-based TV boxes

Campaign
H score88 First: 18.06.2026 20:37 Last: 18.06.2026 20:37 Sources 1

About this happening: NetNut used the Popa botnet and deceptive SDKs on off-brand Android-based smart TVs, streaming media boxes, and unofficial apps to turn home connections into residen...

Latest development: 03.07.2026 12:35

Google disabled all Google accounts used by NetNut for malware command-and-control, updated Google Play Protect to warn Android users, and disabled apps containing the compromised SDKs. The FBI’s seizure banner appeared on netnut.com while netnut.io briefly remained accessible, and Google said the coordinated actions caused significant degradation to NetNut’s proxy network and business operations.

GREYVIBE's Kremlin-aligned role in the Russian cybercrime ecosystem

Threat Actor Meta
H score15 First: 29.05.2026 14:31 Last: 29.05.2026 14:31 Sources 1

About this happening: A newly characterized GREYVIBE actor sits in a grey zone between Kremlin-aligned intelligence work and the Russian cybercrime ecosystem, complicating attribution f...

GreyVibe AI-assisted cyberespionage campaign targeting Ukraine-linked organizations

Campaign
H score39 First: 29.05.2026 01:24 Last: 29.05.2026 01:24 Sources 1

About this happening: GreyVibe is running an AI-assisted cyberespionage campaign against Ukrainian and Ukraine-related organizations, expanding the threat to military, government, civilian,...

Timeline

  1. 12.08.2026 17:09 2 articles · 2h ago

    737 Chrome VPN and proxy extensions intercept browser traffic through SOCKS5 relays

    Initial Disclosure

    Researchers found 737 free VPN and proxy extensions spread across at least 40 Chrome Web Store developer accounts that targeted Russian-speaking users seeking access to blocked services, impersonated 66 VPN and privacy brands, and routed browser sessions through a fixed SOCKS5 server on port 1082. The extensions placed the operator in an adversary-in-the-middle position to observe browser destinations, source IP addresses, TLS SNI values, and plain-HTTP request bodies, while 221 add-ons were removed from the Chrome Web Store and 516 remained active. Researchers also said the operator appears to run a subscription VPN business in Russia, based on a 12-digit taxpayer number and leaked Windows build paths.

    Show sources