All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
A recent study has exposed a fake VPN extension farm that published as many as 737 free VPN and proxy extensions on the Chrome Web Store, which have collectively been installed more than 75,000 times.[1]
Google, even after being aware of this campaign, has so far only removed 221 extensions. That means over 500 fake VPNs — many of which claim to be from reputable VPN providers like NordVPN, Proton VPN, Surfshark, and ExpressVPN — are still available on the official Google store, looking for their next victims.
Worse still, Google is only removing the malicious extensions, not the publisher accounts behind them. That means they can very easily keep churning out new fake VPN extensions and continue harvesting sensitive information, including IP addresses, the websites users visit, and even sensitive credentials they enter on non-HTTPS sites.
Here’s how this fake free VPN campaign exploited genuine users, why you can no longer blindly trust “official” app stores, and how to reliably protect yourself from dodgy free VPNs.
How much can these fake VPNs see
Why Google’s takedowns aren’t enough
What can you do to protect yourself
Bottom line
How the fake VPNs fooled users
This network of fake VPNs was specifically targeting Russian users. That's because Russia is unfortunately one of those countries where government censorship is very high.
It has either banned or severely restricted access to essential internet services such as Instagram, ChatGPT, Discord, and YouTube, as well as almost every single reputable VPN service.
As such, the threat actor is exploiting this desperation among people to access the internet freely and use these region-restricted tools, which is only possible through a Russia VPN.
Socket's research reveals that these fake VPNs made legitimate-looking promises such as "Hides IP and protects data, suitable for any devices and sites." It also states it comes recommended by Yuriy Dud, a renowned Russian journalist. He has no actual connection to this campaign.
Combined with the fact that as many as 274 of these VPN extensions copied around 66 legitimate VPN brands, including Proton VPN, NordVPN, AdGuard VPN, Surfshark, CyberGhost, ExpressVPN, Windscribe, TunnelBear, Cloudflare's 1.1.1.1, and Google's Outline, it's easy to see how users could be fooled.
The threat actor also purposefully impersonated tools such as AmneziaVPN and AntiZapret, which are particularly popular among Russian users when it comes to evading government blocks.
Once users fell for the fake claims and installed these extensions, they routed the users' browser traffic through a shared SOCKS5 proxy infrastructure operated by the threat actor. Essentially, this puts the attacker in a man-in-the-middle position, with the proxy sitting between the user's browser and the internet.
The extensions could even make it appear as though everything was working normally. For example, some extensions displayed a "Protected" status after connecting, despite the fact that the user was simply being routed through the threat actor's proxy infrastructure rather than receiving the protection they expected from a legitimate VPN.
The campaign also used evasion tactics to make its proxy infrastructure harder to detect:
- Of the 522 extensions Socket was able to analyze, 520 configured Chrome to route browser traffic through SOCKS5 proxies on port 1082.
- Another 104 used Cloudflare or Google's DNS-over-HTTPS services to look up the address of their proxy servers. In simple terms, this allowed the extensions to find the proxy's IP address without making a normal DNS request that could expose the threat actor's domain.
Socket also found that the extensions are being used as a customer-acquisition funnel for the threat actor’s paid VPN business in Russia. Many of them, in fact, redirect users toward the paid subscription tier as soon as they are installed.
Moreover, every extension tries to sell users premium VPN server locations, including Japan, Singapore, Canada, Australia, and Turkey, but none of them actually exist.
How much can these fake VPNs see
Because all the traffic was routed through shared proxy infrastructure, the threat actor could potentially see information flowing between a user’s device and the internet. This includes:
- The user's IP address
- The destination websites/domains they were connecting to
- The contents of requests sent over plain HTTP
The last one is arguably the most concerning. It simply means that the attacker could read any information, including your login credentials, you enter on a site that’s not encrypted with HTTPS.
Particularly for Russian citizens who are using these services to bypass their government's internet crackdown, a record of their source IP along with detailed timestamps of their browsing activity could potentially help their internet service provider, or ISP, reveal their identity.
In the wrong hands, your passwords, IP address, and other personally identifiable information could lead to elaborate phishing scams, which could then snowball into identity theft and financial fraud.
Why Google’s takedowns aren’t enough
The most concerning part about this story is Google's failure to stop these malicious attackers from publishing fake VPN extensions in the first place.
When a user sees an extension on the official Chrome Web Store, it's natural to assume that Google has at least checked it. This trust is, unfortunately, part of the attacker's plan.
Almost Secure's research, for instance, found spammy and potentially problematic extensions carrying Google's "Featured" badge, despite Google saying that Chrome team members manually evaluate extensions before awarding it.
Granted, these extensions aren't always easy to identify:
- The threat actor added entire remote-configuration layers to some extensions after Google had already approved them, allowing it to change where they connected without publishing a new version.
- It also used multiple publisher accounts, misleading disclosures to Chrome Web Store reviewers, and techniques such as DNS-over-HTTPS to hide its proxy destinations from analysis.
But that's hardly an excuse!
Consider this: Google is well aware of this fake VPN campaign. After all, it has removed 221 of the 737 extensions. But it hasn't done anything yet about the remaining 516 fake extensions.
What's even more difficult to understand is that Google is only removing the extensions, and not the publisher accounts behind them. 29 of the 30 accounts that have had an extension removed by Google still have active extensions on the Chrome Store.
Furthermore, Socket researchers found that 51 extensions had the same underlying code, but Google removed only one of those extensions. The remaining 50 that are still live have 3,217 installs combined. One of those is named "1.1.1.1 VPN" — with 1,000 installs — and copies Cloudflare's branding outright, yet Google is allowing it to remain live.
If Google believes that sample-blocking extensions is going to deter the attackers, that's unlikely to happen, primarily because of how economically viable the whole campaign is.
The 38 publisher accounts in Socket's source dataset cost the attacker just $190 in total, and given that they published 737 extensions, that works out to $0.258 per extension and roughly $0.00326 per surviving install.
Plus, Google isn't banning the publisher accounts in the first place, so the attacker can continue rolling out new fake VPNs — potentially even getting better at its masquerading skills.
What can you do to protect yourself
If you think you may have installed one of these fake VPN extensions, Socket has published the full list of malicious VPN extensions, so make sure you go through it and check that you’re not using any of them.
Next, confirm that your Chrome browser's proxy configuration has returned to normal. To do so:
- Go to Chrome's settings and type proxy in the top search bar.
- Click Open your computer's proxy settings.
- From there, check that you aren't using a proxy server you don't recognize.
Furthermore, Socket recommends changing the passwords to any of the sites that you visited while using a potentially fake VPN extension. You can do this manually, but a better way to set strong, unique passwords for all of your online accounts is to use a password manager.
If you're concerned about your sensitive data being shared and exploited in the wild, you can also use an identity theft protection service. It can comb through online databases as well as hidden parts of the internet, such as the dark web, to alert you if it finds your information anywhere.
Finally, the best way to protect yourself from dodgy VPNs is to stay away from free VPNs. Because they also have to make money somehow, they often resort to harvesting user data and selling it to advertising or data brokers.
The best-case scenario with free VPNs is when they're essentially only designed to introduce you to a provider's main paid-for service, such as Proton VPN.
Bottom line
VPNs are essential privacy tools that have become more popular over the last few years, particularly because of their ability to help people fight back against government censorship and unblock geo-restricted content.
However, a threat actor has been found exploiting this demand in Russia, using a network of fake VPN extensions to steal users’ IP addresses and browser activity.
Unfortunately, Google is doing very little to improve the situation. In addition to letting more than 500 of these fake extensions remain live, it has also been found wanting when it comes to improving the security of its store.
[1] 737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection