• The new season of NFL Fantasy is now open for registrations. Anyone wishing to participate please sign up before August 16 2026.
    EPL and NFL Pickem pools are now open for registration
    EPL Ultimate Team is now open for registration. The new season kicks off on August 21 2026.
    NEW GAME: Club Manager is now live. Go register your team for the upcoming season.

Beware of Fake VPNs in Chrome Store Technology 

  • Date Created Jason
  • Last Reply Jason
  • Reply Count 0
  • View Count 7
  • Thread Participants
Thread Insights AI
9/10

The post provides a comprehensive overview of the risks associated with fake VPNs, supported by data and examples. It is clear and relevant to users concerned about online security, although a brief summary at the end could enhance clarity.

Jason Contributor
A new report by Socket shows that more than 50,000 Chrome users are using fake VPNs that steal their data. In the world of online security, VPNs are often the tool many users turn to. They help direct your internet traffic through a secure, encrypted channel, preventing your metadata from spilling out into the open. However, the key to this arrangement is trust; if the VPN itself is compromised, you might be trading one set of risks for a guaranteed breach.

Recently, a concerning report from Socket revealed that over 700 fake VPN apps have infiltrated the Chrome Web Store. These extensions, some free and others paid, often masquerade as legitimate services from well-known cybersecurity providers, enticing users into granting them unrestricted access to their networks and browsing activities.

Socket's analysis focused on 737 dubious Chrome extensions claiming to offer VPN and SOCKS5 proxy services. Alarmingly, they discovered that many of these apps were selling access to non-existent VPN servers, tracking users' online activities by hijacking their proxy settings, and impersonating reputable VPN brands like NordVPN and Surfshark.

The cybersecurity team at Socket, which also offers tools for developers to analyse AI-generated code for malicious behaviour, found that these extensions were published by just 40 developer accounts and had amassed a staggering 75,486 installs. They conducted a detailed examination of 525 of these extensions, revealing some troubling findings:
  • Plagiarism: A significant 274 out of the 525 extensions copied branding and logos from 66 established VPN platforms, including Proton VPN, Surfshark, NordVPN, ExpressVPN, CyberGhost, and TunnelBear.
  • Impersonation: Two extensions specifically mimicked AmneziaVPN and AntiZapret, which are commonly used to bypass internet censorship.
  • Security Flaws: The extensions directed all traffic through a fixed SOCKS5 proxy without offering split tunnelling or per-site controls, meaning all your online activities would be routed through the same server.
Since you can't rely on app store review processes alone, you need some way to spot fake extensions before they embed spyware into your browser. You can't be expected to reverse-engineer every extension's manifest file like Socket did, but thankfully you don't have to, because there are easier ways to tell if something might be amiss.
  • Install extensions by following a link directly from the VPN provider's official website, not the search bar on the Web Store or Google Play.
  • Always read reviews before installing a new browser extension. If too many people are complaining about security concerns, avoid it.
  • Before you install a Chrome Web Store extension, look past the app listing and user reviews to the developer account tied to that app as well. Check if the account is officially associated with the VPN provider and see if Web Store reviews flag security concerns on their other apps too.
  • Use a tool like WhatIsMyIPAddress.com to check your currently visible IP address. Confirm that it matches the IP address displayed in your VPN extension's UI.
  • Run a DNS leak check while your VPN is on to make sure that it's working properly, not merely concealing your IP address but also encrypting your DNS queries. If either your IP address, general location, or internet service provider (ISP) shows up in the test results, that's a red flag.
 
Previous Thread
BlackEyed Pete BlackEyed Pete 1 24
No next thread
Back
Top Bottom