Skip to main content

AI-Generated Fake VPN Chrome Extensions

Published 9 min read

Fake VPN extensions cover: a fake VPN Chrome extension routing all browsing through 15 attacker SOCKS5 proxy servers, with stat tiles reading 350-plus clones, 32-plus accounts, and only 14 removed.

TL;DR — Unit 42 (Palo Alto Networks) is tracking a threat actor running an automated factory of fake VPN Chrome extensions that routes all victim browsing through a shared set of attacker-controlled SOCKS5 proxies. Since first reporting in May 2026, Unit 42 has detected over 350 new cloned extensions across at least 32 fresh Chrome Web Store accounts, with brand-impersonation targets growing from 4 to 15. Only 14 extensions have been removed so far — the rest remain live, with more than 3,000 installations observed and the operator holding visibility into every request.

About this analysis. This is a PhishEye Threat Research summary of findings published by Unit 42 (Palo Alto Networks) on 21 July 2026. All indicators are attributed to Unit 42 and defanged. PhishEye did not independently discover this campaign; our contribution here is defensive analysis and guidance for teams that need to detect and respond to it.

What Unit 42 reported

On 22 May 2026, Unit 42 first publicly disclosed a threat actor operating a factory of dozens of fake VPN Chrome extensions, each routing all user browsing traffic through the same set of 15 hardcoded SOCKS5 proxy servers. Nearly two months later, according to Unit 42, the campaign is not only still active but cloning new extensions at an increasing pace. Unit 42's researchers documented over 350 new extensions since the initial report.

The scale-out is deliberate and industrialized. Unit 42 reported that the actor has stood up at least 32 new Google Chrome Web Store accounts, typically carrying 5 to 10 extensions each — though some run well beyond that. Beyond the 15 publisher email accounts identified in May, new example accounts include noriuman26@gmail[.]com (14 extensions) and vale99505@gmail[.]com (12 extensions). With 350+ extensions detected, the 32 accounts Unit 42 names are a floor rather than the full set. The number of brands being impersonated has grown from 4 to 15.

The takedown gap is the part defenders should sit with. Unit 42 reported that only 14 extensions from this campaign have been removed from the Chrome Web Store to date. Every other extension remains active, and more than 3,000 installations have been observed across the campaign.

Why "VPN" is the wrong word for these

A legitimate VPN extension establishes an encrypted tunnel that protects traffic in transit. These do not. Unit 42 documented that the extensions provide none of the encrypted protection users expect from reputable VPN products. Instead, all communication is funneled through the operator's SOCKS5 proxies — meaning the threat actor sits in the path of every request and has access to all communications. SOCKS5 is a general-purpose proxy protocol; it carries whatever the client sends, encrypted or not, but it grants the proxy operator full visibility of connection metadata and any unencrypted content. A user installs software they believe protects their privacy and instead hands their entire browsing session to an adversary.

This is the core deception. The brand impersonation and the "VPN" framing are trust primitives — they exist to make a proxy interception tool look like a security product.

The automation tells

Unit 42's infrastructure analysis points to heavy automation rather than manual tradecraft, which is what makes the 350+ figure plausible and worrying.

Proxy domains are bulk-registered on a small number of distinct days. Unit 42 noted 6 domains registered on 2026-04-05 and 19 domains registered on 2026-05-20. Most of these domains are co-hosted on just two servers — 95.163.244[.]138 and 212.192.14[.]75 — which Unit 42 reads as a sign of automated infrastructure provisioning. Bulk registration plus tight co-hosting is a hunting opportunity: it means the campaign's backend is far more concentrated than its 350+ storefront presence suggests.

The extensions themselves also evolve quietly. Unit 42 documented that between versions 1.0.0 and 1.0.1 of extension pddhejgmgakilndagfaffgochjojogfp, the actor added a new host permission and altered the core logic to fetch a QR code dynamically from a remote server. That change let them update the QR link without shipping a new extension release each time — a small permission diff that converts a static artifact into a remotely reconfigurable one. Anyone reviewing extension updates by version number alone, rather than by permission delta, would miss it.

Backend resilience is built in as well. Unit 42 reported that 15 hardcoded static IPs cover US and EU proxy nodes, while operator-controlled hostnames handle Japan, Singapore, Canada, Australia and Turkey — allowing the actor to rotate those regional backends without pushing an extension update at all. The static IPs are the durable indicators; the hostname-fronted regions are designed to move.

Why AI-generated cloning matters here

The "AI-generated" framing in Unit 42's reporting is not incidental. Producing 350+ distinct, brand-plausible extension listings — with varied names, descriptions and iconography across 32 accounts — is exactly the kind of repetitive, template-driven content generation that cheap AI tooling makes trivial. The economics have inverted: the cost of manufacturing a convincing fake listing has collapsed, while the cost of reviewing and removing each one has not. A campaign that can mint clones faster than a marketplace can vet them will, on current evidence, stay ahead of takedowns. The 14-removed-out-of-350+ ratio is the visible result of that asymmetry.

For digital-risk teams, the lesson is that brand impersonation is now a volume problem, not a one-off. Monitoring for a single lookalike listing is insufficient when the adversary's model is to flood the marketplace and rely on survivorship.

What defenders should do

  • Inventory installed browser extensions across the fleet. Match extension IDs against the sample published by Unit 42 (below) and flag any VPN or "privacy" extension whose publisher account is unfamiliar or recently created.
  • Alert on the SOCKS5 proxy IPs and domains. Add the 15 static server IPs and the proxy domains to egress monitoring and DNS/RPZ blocklists. These are the campaign's durable, concentrated indicators — traffic to them from a corporate endpoint is a strong signal of a compromised browser.
  • Review extension permission deltas, not just versions. The pddhejgmgakilndagfaffgochjojogfp example shows benign-looking point releases quietly adding host permissions. Diff manifests on update; treat any new broad host permission on a VPN/privacy extension as suspicious.
  • Enforce an extension allowlist via enterprise browser policy. For managed Chrome, restrict installs to a vetted allowlist (ExtensionInstallAllowlist / ExtensionInstallBlocklist). This closes the entire class rather than chasing individual clones.
  • Treat "free VPN" extensions as high-risk by default. Communicate to users that a browser extension that proxies all traffic is a full man-in-the-middle position; free ones with no verifiable operator are not privacy tools.
  • Hunt on the co-hosting infrastructure. Pivot from the two shared hosting servers to surface additional campaign domains that may predate their appearance in any extension listing.
  • Report clones, but do not rely on takedowns. Given the 14-of-350+ removal rate, submit abuse reports for discovered listings while assuming the marketplace will not remove them promptly.

Indicators (attributed to Unit 42, defanged)

Defanged; re-fang by replacing [.] with . — these are live/known-malicious, handle in isolation. Unit 42 reported over 350 extensions and a large set of proxy domains; the blocks below are the representative samples published by Unit 42, not the full lists.

# Publisher email accounts (examples; part of 32+ Chrome Web Store accounts)
noriuman26@gmail[.]com    # 14 extensions
vale99505@gmail[.]com     # 12 extensions
# Example proxy domains (samples of a larger set)
vaultvpn[.]space
silashield[.]space
shieldtunnel[.]space
turbotunnel[.]space
echosecure[.]space
bezopasnet[.]space
zenshield[.]space
skyproxy[.]space
routekeeper[.]space
stealthpath[.]space
securepulse[.]space
ironproxy[.]space
primeproxy[.]space
maskirovka[.]space
skorostvpn[.]space
cloudmask[.]space
neoncloak[.]space
sverchvpn[.]space
nimbusshield[.]space
murvpn[.]space
horizonguard[.]space
pauktun[.]space
atlasvpn[.]space
zhuzhvpn[.]space
netroutehub[.]space
vpnfasters[.]space
routeshield[.]space
gusenvpn[.]online
spidervpn[.]online
# Hardcoded SOCKS5 proxy server IPs (15 static US/EU nodes)
103.35.189[.]225
5.180.30[.]122
185.252.215[.]98
103.35.191[.]173
178.130.47[.]129
45.89.110[.]227
80.92.204[.]47
194.150.220[.]163
80.92.206[.]84
94.131.118[.]39
80.92.204[.]33
86.104.74[.]110
185.252.215[.]97
94.131.118[.]237
5.180.30[.]15
# Co-hosting infrastructure (proxy-domain hosting servers)
95.163.244[.]138
212.192.14[.]75
# Example fake VPN Chrome extension IDs (samples of 350+)
dlbaieojjjcjmmeohkcaadjpgeelogeb
almdngpalkpacjoeffkhacdjjimijjnf
amohbpndmbcjecjnghhaeeanohiflfpj
npjjbjijmdoicmkjmalabbkchhphnhkd
mlcdgeihjfnedibbbadinnjilgjnplip
cdfajacnjbaigbjnpdjeeapephdnoeng
hjmjmbiaafeggmgadknfbkeehppmhejk
flpkiejgfikibbkjnikdcaonkfindfgb
ihpdbailkcljcclemifagdnfmgpfnfbi
cabdahinacflcaaagobghohleefogogk
plciffedekbipeophpkkjlilcdfnnkic
ijilplnnjkjklkmhbklfnpnlnjpbfaie
ommmigkmgbilkbggodbipeffbjdbcook
pmmneeeipikleggeclkinacjcjnegfbm
fkmbekmghpabdjfobhpbnmpakibmfecm
edakhofdfkcdhnmcjaacekhfgochaceo
pbecllekjbdgokpkfmgaggfmghfdipkn
kjbelgiekopnehkjmcpoiiopmfhbcokn
celjebeafmieepphodddabmegonmanoo
fgdmoacjelpcghceahplbfgepnmlgnna
pddhejgmgakilndagfaffgochjojogfp    # host-permission change between v1.0.0 and v1.0.1

Sources

FAQ

What is the fake VPN extension campaign Unit 42 documented? It is a threat actor running an automated factory of fake VPN Chrome extensions that route all of a victim's browsing through attacker-controlled SOCKS5 proxies instead of providing real encrypted protection. Unit 42 has detected over 350 cloned extensions since May 2026.

Do these extensions actually protect my traffic? No. Unit 42 reported that they provide none of the encrypted protection reputable VPNs offer. All communication passes through the operator's SOCKS5 proxies, so the threat actor has access to every request the browser makes.

How many extensions have been taken down? According to Unit 42, only 14 extensions had been removed from the Chrome Web Store at the time of reporting. All others remained active, with more than 3,000 installations observed across the campaign.

What makes this campaign hard to stop? Automation and volume. Unit 42 documented at least 32 Chrome Web Store accounts (a floor, not the full set), bulk-registered domains co-hosted on two servers, and backend hostnames that rotate regional proxies without an extension update — letting the actor produce clones faster than the marketplace removes them.

What should organizations do right now? Inventory installed browser extensions against Unit 42's published IDs, block the 15 SOCKS5 proxy IPs and associated domains at egress, enforce an enterprise extension allowlist, and review permission changes on updates rather than trusting version numbers.


About the authors

PhishEye Threat Research analyzes brand-impersonation and phishing campaigns to help defenders act on emerging threats. This article summarizes and adds defensive context to research originally published by Unit 42 (Palo Alto Networks) on 21 July 2026 by Ravindu De Silva and Nabeel Mohamed; all indicators, figures and attribution belong to Unit 42, and PhishEye did not independently discover this campaign.