Proliferation of AI-Generated Fake VPN Extensions

    Date: 07/22/2026

    Severity: High

    Summary

    Researchers first exposed this campaign on May 22, 2026, identifying fake Chrome VPN extensions that redirected user traffic through attacker-controlled SOCKS5 proxy servers. Nearly two months later, the operation has expanded significantly, with 350+ new malicious extensions and at least 32 new Chrome Web Store accounts hosting cloned VPN apps. The threat actor has also increased its brand impersonation efforts from 4 to 15 VPN brands, while only a small number of extensions have been removed. Most of the malicious extensions remain available on the Chrome Web Store and have accumulated over 3,000 installations. Instead of providing encrypted VPN protection, the extensions route all browsing traffic through attacker-controlled SOCKS5 proxies, allowing potential interception of user communications. The infrastructure relies on 15 hardcoded IPs for US and European proxies, while operator-controlled hostnames support Japan, Singapore, Canada, Australia, and Turkey, enabling backend changes without updating the extensions.

    Indicators of Compromise (IOC) List 

    Domains/URLs

    vaultvpn.space

    silashield.space

    shieldtunnel.space

    turbotunnel.space

    echosecure.space

    bezopasnet.space

    zenshield.space

    skyproxy.space

    routekeeper.space

    stealthpath.space

    securepulse.space

    ironproxy.space

    primeproxy.space

    maskirovka.space

    skorostvpn.space

    cloudmask.space

    neoncloak.space

    sverchvpn.space

    nimbusshield.space

    murvpn.space

    horizonguard.space

    pauktun.space

    atlasvpn.space

    zhuzhvpn.space

    netroutehub.space

    vpnfasters.space

    routeshield.space

    gusenvpn.online

    spidervpn.online

    IP Address 

    103.35.189.225

    5.180.30.122

    185.252.215.98

    103.35.191.173

    178.130.47.129

    45.89.110.227

    80.92.204.47

    194.150.220.163

    80.92.206.84

    94.131.118.39

    80.92.204.33

    86.104.74.110

    185.252.215.97

    94.131.118.237

    5.180.30.15

    Fake VPN Chrome Extensions

    dlbaieojjjcjmmeohkcaadjpgeelogeb

    almdngpalkpacjoeffkhacdjjimijjnf

    amohbpndmbcjecjnghhaeeanohiflfpj

    npjjbjijmdoicmkjmalabbkchhphnhkd

    mlcdgeihjfnedibbbadinnjilgjnplip

    cdfajacnjbaigbjnpdjeeapephdnoeng

    hjmjmbiaafeggmgadknfbkeehppmhejk

    flpkiejgfikibbkjnikdcaonkfindfgb

    ihpdbailkcljcclemifagdnfmgpfnfbi

    cabdahinacflcaaagobghohleefogogk

    plciffedekbipeophpkkjlilcdfnnkic

    ijilplnnjkjklkmhbklfnpnlnjpbfaie

    ommmigkmgbilkbggodbipeffbjdbcook

    pmmneeeipikleggeclkinacjcjnegfbm

    fkmbekmghpabdjfobhpbnmpakibmfecm

    edakhofdfkcdhnmcjaacekhfgochaceo

    pbecllekjbdgokpkfmgaggfmghfdipkn

    kjbelgiekopnehkjmcpoiiopmfhbcokn

    celjebeafmieepphodddabmegonmanoo

    fgdmoacjelpcghceahplbfgepnmlgnna

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection 

    Detection Query 1 :

    domainname like "pauktun.space" or url like "pauktun.space" or siteurl like "pauktun.space" or domainname like "gusenvpn.online" or url like "gusenvpn.online" or siteurl like "gusenvpn.online" or domainname like "zhuzhvpn.space" or url like "zhuzhvpn.space" or siteurl like "zhuzhvpn.space" or domainname like "routekeeper.space" or url like "routekeeper.space" or siteurl like "routekeeper.space" or domainname like "ironproxy.space" or url like "ironproxy.space" or siteurl like "ironproxy.space" or domainname like "securepulse.space" or url like "securepulse.space" or siteurl like "securepulse.space" or domainname like "horizonguard.space" or url like "horizonguard.space" or siteurl like "horizonguard.space" or domainname like "echosecure.space" or url like "echosecure.space" or siteurl like "echosecure.space" or domainname like "bezopasnet.space" or url like "bezopasnet.space" or siteurl like "bezopasnet.space" or domainname like "routeshield.space" or url like "routeshield.space" or siteurl like "routeshield.space" or domainname like "vaultvpn.space" or url like "vaultvpn.space" or siteurl like "vaultvpn.space" or domainname like "nimbusshield.space" or url like "nimbusshield.space" or siteurl like "nimbusshield.space" or domainname like "maskirovka.space" or url like "maskirovka.space" or siteurl like "maskirovka.space" or domainname like "stealthpath.space" or url like "stealthpath.space" or siteurl like "stealthpath.space" or domainname like "netroutehub.space" or url like "netroutehub.space" or siteurl like "netroutehub.space" or domainname like "spidervpn.online" or url like "spidervpn.online" or siteurl like "spidervpn.online" or domainname like "zenshield.space" or url like "zenshield.space" or siteurl like "zenshield.space" or domainname like "shieldtunnel.space" or url like "shieldtunnel.space" or siteurl like "shieldtunnel.space" or domainname like "atlasvpn.space" or url like "atlasvpn.space" or siteurl like "atlasvpn.space" or domainname like "skyproxy.space" or url like "skyproxy.space" or siteurl like "skyproxy.space" or domainname like "vpnfasters.space" or url like "vpnfasters.space" or siteurl like "vpnfasters.space" or domainname like "sverchvpn.space" or url like "sverchvpn.space" or siteurl like "sverchvpn.space" or domainname like "neoncloak.space" or url like "neoncloak.space" or siteurl like "neoncloak.space" or domainname like "silashield.space" or url like "silashield.space" or siteurl like "silashield.space" or domainname like "turbotunnel.space" or url like "turbotunnel.space" or siteurl like "turbotunnel.space" or domainname like "primeproxy.space" or url like "primeproxy.space" or siteurl like "primeproxy.space" or domainname like "murvpn.space" or url like "murvpn.space" or siteurl like "murvpn.space" or domainname like "cloudmask.space" or url like "cloudmask.space" or siteurl like "cloudmask.space" or domainname like "skorostvpn.space" or url like "skorostvpn.space" or siteurl like "skorostvpn.space"

    Detection Query 2 :

    dstipaddress IN ("80.92.206.84","185.252.215.97","80.92.204.47","178.130.47.129","94.131.118.39","94.131.118.237","80.92.204.33","5.180.30.15","5.180.30.122","86.104.74.110","45.89.110.227","185.252.215.98","103.35.191.173","194.150.220.163","103.35.189.225") or srcipaddress IN ("80.92.206.84","185.252.215.97","80.92.204.47","178.130.47.129","94.131.118.39","94.131.118.237","80.92.204.33","5.180.30.15","5.180.30.122","86.104.74.110","45.89.110.227","185.252.215.98","103.35.191.173","194.150.220.163","103.35.189.225")

    Reference:    

    https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2026-07-21-Proliferation-of-AI-Generated-Fake-VPN-Extensions.txt                       


    Tags

    AIUnited StatesEuropeJapanSingaporeCanadaAustraliaTurkey

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags