Date: 07/22/2026
Severity: High
Summary
Researchers first exposed this campaign on May 22, 2026, identifying fake Chrome VPN extensions that redirected user traffic through attacker-controlled SOCKS5 proxy servers. Nearly two months later, the operation has expanded significantly, with 350+ new malicious extensions and at least 32 new Chrome Web Store accounts hosting cloned VPN apps. The threat actor has also increased its brand impersonation efforts from 4 to 15 VPN brands, while only a small number of extensions have been removed. Most of the malicious extensions remain available on the Chrome Web Store and have accumulated over 3,000 installations. Instead of providing encrypted VPN protection, the extensions route all browsing traffic through attacker-controlled SOCKS5 proxies, allowing potential interception of user communications. The infrastructure relies on 15 hardcoded IPs for US and European proxies, while operator-controlled hostnames support Japan, Singapore, Canada, Australia, and Turkey, enabling backend changes without updating the extensions.
Indicators of Compromise (IOC) List
Domains/URLs | vaultvpn.space silashield.space shieldtunnel.space turbotunnel.space echosecure.space bezopasnet.space zenshield.space skyproxy.space routekeeper.space stealthpath.space securepulse.space ironproxy.space primeproxy.space maskirovka.space skorostvpn.space cloudmask.space neoncloak.space sverchvpn.space nimbusshield.space murvpn.space horizonguard.space pauktun.space atlasvpn.space zhuzhvpn.space netroutehub.space vpnfasters.space routeshield.space gusenvpn.online spidervpn.online |
IP Address | 103.35.189.225 5.180.30.122 185.252.215.98 103.35.191.173 178.130.47.129 45.89.110.227 80.92.204.47 194.150.220.163 80.92.206.84 94.131.118.39 80.92.204.33 86.104.74.110 185.252.215.97 94.131.118.237 5.180.30.15 |
Fake VPN Chrome Extensions | dlbaieojjjcjmmeohkcaadjpgeelogeb almdngpalkpacjoeffkhacdjjimijjnf amohbpndmbcjecjnghhaeeanohiflfpj npjjbjijmdoicmkjmalabbkchhphnhkd mlcdgeihjfnedibbbadinnjilgjnplip cdfajacnjbaigbjnpdjeeapephdnoeng hjmjmbiaafeggmgadknfbkeehppmhejk flpkiejgfikibbkjnikdcaonkfindfgb ihpdbailkcljcclemifagdnfmgpfnfbi cabdahinacflcaaagobghohleefogogk plciffedekbipeophpkkjlilcdfnnkic ijilplnnjkjklkmhbklfnpnlnjpbfaie ommmigkmgbilkbggodbipeffbjdbcook pmmneeeipikleggeclkinacjcjnegfbm fkmbekmghpabdjfobhpbnmpakibmfecm edakhofdfkcdhnmcjaacekhfgochaceo pbecllekjbdgokpkfmgaggfmghfdipkn kjbelgiekopnehkjmcpoiiopmfhbcokn celjebeafmieepphodddabmegonmanoo fgdmoacjelpcghceahplbfgepnmlgnna |
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | domainname like "pauktun.space" or url like "pauktun.space" or siteurl like "pauktun.space" or domainname like "gusenvpn.online" or url like "gusenvpn.online" or siteurl like "gusenvpn.online" or domainname like "zhuzhvpn.space" or url like "zhuzhvpn.space" or siteurl like "zhuzhvpn.space" or domainname like "routekeeper.space" or url like "routekeeper.space" or siteurl like "routekeeper.space" or domainname like "ironproxy.space" or url like "ironproxy.space" or siteurl like "ironproxy.space" or domainname like "securepulse.space" or url like "securepulse.space" or siteurl like "securepulse.space" or domainname like "horizonguard.space" or url like "horizonguard.space" or siteurl like "horizonguard.space" or domainname like "echosecure.space" or url like "echosecure.space" or siteurl like "echosecure.space" or domainname like "bezopasnet.space" or url like "bezopasnet.space" or siteurl like "bezopasnet.space" or domainname like "routeshield.space" or url like "routeshield.space" or siteurl like "routeshield.space" or domainname like "vaultvpn.space" or url like "vaultvpn.space" or siteurl like "vaultvpn.space" or domainname like "nimbusshield.space" or url like "nimbusshield.space" or siteurl like "nimbusshield.space" or domainname like "maskirovka.space" or url like "maskirovka.space" or siteurl like "maskirovka.space" or domainname like "stealthpath.space" or url like "stealthpath.space" or siteurl like "stealthpath.space" or domainname like "netroutehub.space" or url like "netroutehub.space" or siteurl like "netroutehub.space" or domainname like "spidervpn.online" or url like "spidervpn.online" or siteurl like "spidervpn.online" or domainname like "zenshield.space" or url like "zenshield.space" or siteurl like "zenshield.space" or domainname like "shieldtunnel.space" or url like "shieldtunnel.space" or siteurl like "shieldtunnel.space" or domainname like "atlasvpn.space" or url like "atlasvpn.space" or siteurl like "atlasvpn.space" or domainname like "skyproxy.space" or url like "skyproxy.space" or siteurl like "skyproxy.space" or domainname like "vpnfasters.space" or url like "vpnfasters.space" or siteurl like "vpnfasters.space" or domainname like "sverchvpn.space" or url like "sverchvpn.space" or siteurl like "sverchvpn.space" or domainname like "neoncloak.space" or url like "neoncloak.space" or siteurl like "neoncloak.space" or domainname like "silashield.space" or url like "silashield.space" or siteurl like "silashield.space" or domainname like "turbotunnel.space" or url like "turbotunnel.space" or siteurl like "turbotunnel.space" or domainname like "primeproxy.space" or url like "primeproxy.space" or siteurl like "primeproxy.space" or domainname like "murvpn.space" or url like "murvpn.space" or siteurl like "murvpn.space" or domainname like "cloudmask.space" or url like "cloudmask.space" or siteurl like "cloudmask.space" or domainname like "skorostvpn.space" or url like "skorostvpn.space" or siteurl like "skorostvpn.space" |
Detection Query 2 : | dstipaddress IN ("80.92.206.84","185.252.215.97","80.92.204.47","178.130.47.129","94.131.118.39","94.131.118.237","80.92.204.33","5.180.30.15","5.180.30.122","86.104.74.110","45.89.110.227","185.252.215.98","103.35.191.173","194.150.220.163","103.35.189.225") or srcipaddress IN ("80.92.206.84","185.252.215.97","80.92.204.47","178.130.47.129","94.131.118.39","94.131.118.237","80.92.204.33","5.180.30.15","5.180.30.122","86.104.74.110","45.89.110.227","185.252.215.98","103.35.191.173","194.150.220.163","103.35.189.225") |
Reference:
https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2026-07-21-Proliferation-of-AI-Generated-Fake-VPN-Extensions.txt