AlienVault OTX flags a coordinated cluster of 31 Russian-language Chrome extensions impersonating VPN access for RuTracker, YouTube, Telegram, Instagram, ChatGPT, and Netflix. The extensions are published from three linked Google accounts, share a single malicious codebase, and collectively reach roughly 356,000 users, with the RuTracker-themed extension alone at about 200,000 installs. The operational model is not classic payload-heavy malware; it is browser-resident traffic interception. The extensions likely abuse Chrome extension capabilities to observe, modify, reroute, or proxy user traffic, then pull dynamic configuration from attacker-controlled infrastructure such as api.hhos.ru and de34.rapidstaticserve.cc.
The collective objective appears to be monetizable interception at scale: session cookies, bearer tokens, credentials entered into web flows, search and browsing telemetry, and proxy-mediated traffic that can be sold, replayed, or used for follow-on account takeover. The use of blocked-platform VPN lures suggests users are intentionally seeking circumvention tools and may accept excessive permissions, ignore warnings, or disable enterprise browser policy. For enterprises, the risk is highest where users access SaaS, email, developer consoles, cloud admin portals, SSO, password managers, or financial systems from an infected browser profile.
Treat this as a credential and session exposure event even if no traditional stealer binary is present. Browser extensions can sit inside the trust boundary, read page content after decryption, and bypass many network controls because traffic originates from chrome.exe or a user-approved browser process.
Threat Actor / Malware Profile
Attribution is currently unknown. The actor profile is consistent with Russian-language opportunistic cybercrime or traffic-monetization operators rather than a named APT. The campaign relies on social engineering around censorship circumvention and platform access, not exploit delivery.
Distribution method: malicious Chrome Web Store extensions themed as VPN or unblocker services, clustered under linked publisher accounts to survive takedowns and rebrand quickly.
Payload behavior: shared codebase across 31 extensions, dynamic remote configuration, browser proxy manipulation, traffic interception, remote-control capability, and potential exfiltration of tokens, cookies, form data, and browsing metadata.
C2 communication: web-based callbacks to attacker hostnames including api.hhos.ru and de34.rapidstaticserve.cc. Expect HTTPS beaconing, JSON or encoded config pulls, domain rotation, CDN or static-hosting abuse, and low-and-slow polling to blend with normal browser telemetry.
Persistence mechanism: Chrome extension installation under the user profile, enterprise policy gaps, sync propagation across a user’s signed-in Chrome profiles, and reinstallation through lookalike listings after removal.
Anti-analysis techniques: benign store descriptions, permission justification through VPN functionality, remote configuration that activates only after install, domain or path rotation, code obfuscation in extension JavaScript, and delayed execution to evade store review and sandbox detonation.
Relevant MITRE ATT&CK mapping: T1176 Browser Extensions, T1557 Adversary-in-the-Middle, T1090 Proxy, T1071.001 Web Protocols, T1555.003 Credentials from Web Browsers, T1539 Steal Web Session Cookie, and T1105 Ingress Tool Transfer where additional scripts or configs are fetched.
IOC Analysis
Indicator types present are hostnames and file hashes. No IPv4 or URL paths were included in the pulse sample, so teams should expand resolution passively rather than hard-coding only current A records.
Hostnames: api.hhos.ru and de34.rapidstaticserve.cc should be blocked at DNS, proxy, SWG, EDR network, and browser isolation layers. Alert on any chrome.exe, msedge.exe, firefox.exe, or headless browser process resolving or connecting to these names. Because dynamic configuration is central to the campaign, hunt for failed lookups as well; repeated NXDOMAIN or sinkhole hits can identify already-installed extensions after infrastructure rotation.
File hashes: the SHA256 values are useful for payload or extension artifact matching if EDR captured CRX downloads, unpacked extension folders, cached extension updates, or dropped JavaScript bundles. Hashes rotate quickly in extension ecosystems, so use them for retro-hunts and precise blocking, not as the sole control.
Operationalization: push indicators to DNS RPZ, secure web gateway custom block categories, EDR custom indicators, firewall FQDN objects where supported, and SIEM watchlists. Enrich with passive DNS, TLS certificate transparency, Chrome Web Store publisher history, extension ID inventory, CRX download telemetry, proxy PAC changes, and browser policy audit logs. Useful tooling includes Chrome Enterprise policy reports, ExtensionManifestV2/ExtensionManifestV3 inventory, Sysmon DNS and network events, Microsoft Defender for Endpoint browser network events, Zeek or Suricata logs, and CyberChef or jq for decoding extension configs and base64-like blobs.
Detection Engineering
---
title: Fake VPN Extension C2 Resolution - api.hhos.ru and rapidstaticserve.cc
id: 7d18b6f7-8d2f-4e2d-9f16-otxvpnfarm001
status: experimental
description: Detects DNS queries for infrastructure tied to a Russian-language fake VPN Chrome extension proxy farm that performs traffic interception and remote configuration.
author: Security Arsenal
references:
- https://riskyplugins.com/threat-library/russian-vpn-proxy-farm
date: 2026/09/29
logsource:
category: dns
product: windows
level: high
detection:
selection:
QueryName|contains:
- api.hhos.ru
- rapidstaticserve.cc
filter_known_clients:
Image|endswith:
- '\svchost.exe'
condition: selection and not 1 of filter_*
falsepositives:
- Threat research, sandbox detonation, or vendor validation traffic
fields:
- QueryName
- Image
- User
- Computer
tags:
- attack.t1071.001
- attack.t1176
- attack.t1090
---
title: Browser Process Network Connection To Fake VPN Proxy Farm
id: 2c9c59d5-bf5f-4f32-98d6-otxvpnfarm002
status: experimental
description: Detects Chrome, Edge, or Firefox establishing network connections to domains associated with malicious VPN-impersonation extensions.
author: Security Arsenal
references:
- https://riskyplugins.com/threat-library/russian-vpn-proxy-farm
date: 2026/09/29
logsource:
category: network_connection
product: windows
level: critical
detection:
selection_process:
Image|endswith:
- '\chrome.exe'
- '\msedge.exe'
- '\firefox.exe'
selection_dest:
DestinationHostname|contains:
- api.hhos.ru
- rapidstaticserve.cc
condition: selection_process and selection_dest
falsepositives:
- Security research, controlled reproduction, or deception environments
fields:
- Image
- User
- DestinationHostname
- DestinationIp
- DestinationPort
- Protocol
tags:
- attack.t1071.001
- attack.t1176
- attack.t1557
---
title: Suspicious User Proxy Configuration Change Around Browser Activity
id: b63662e0-52d6-42c3-9a93-otxvpnfarm003
status: experimental
description: Detects user-level proxy or PAC changes that may indicate browser extension proxy abuse, traffic interception, or manual circumvention tooling.
author: Security Arsenal
references:
- https://riskyplugins.com/threat-library/russian-vpn-proxy-farm
date: 2026/09/29
logsource:
category: registry_set
product: windows
level: medium
detection:
selection_key:
TargetObject|contains: '\Software\Microsoft\Windows\CurrentVersion\Internet Settings'
selection_value:
TargetObject|endswith:
- '\ProxyEnable'
- '\ProxyServer'
- '\AutoConfigURL'
filter_chrome_policy:
Image|endswith:
- '\chrome.exe'
- '\msedge.exe'
condition: selection_key and selection_value and not filter_chrome_policy
falsepositives:
- Corporate VPN clients, ZTNA agents, pilot proxy deployments, managed browser policy
fields:
- Image
- User
- TargetObject
- Details
- ProcessGuid
tags:
- attack.t1090
- attack.t1557
- attack.t1176
let BadHosts = dynamic(["api.hhos.ru", "de34.rapidstaticserve.cc"]);
let BadHashes = dynamic([
"0fa1d38b9dd7e089db3b47407cb684475e184cd6e0683ec252fe3218f169599c",
"2052a339947490fb10296e6e1f9857a83705a3716a528ed22c65e098b1a593e1",
"29ecbcd44d9e1121c2ba2edad26c214036ab83eeb41f7758e4252ae8f92e3393",
"2a5a967d232d97ff3a4983eefeac69347eaf88d19efdd1e783b2d0268226e894",
"2ebeb17cdbeab7547c8dfebade198739e0f1c5dbf9de2977ce318bfcf132d318",
"3477d7c15ed67ba56295a2a64e525ce3ced65be292b873d154ad2e88de340ae6"]);
union isfuzzy=true
(DeviceNetworkEvents
| where Timestamp > ago(14d)
| where RemoteUrl has_any (BadHosts) or RemoteIP in (externaldata(indicator:string)[@"placeholder"] with (format="txt"))
| where InitiatingProcessFileName in~ ("chrome.exe","msedge.exe","firefox.exe")
| project Timestamp, DeviceName, InitiatingProcessAccountName, InitiatingProcessFileName, RemoteUrl, RemoteIP, RemotePort, ActionType, ReportId),
(DeviceProcessEvents
| where Timestamp > ago(14d)
| where FileName in~ ("chrome.exe","msedge.exe","firefox.exe")
| where ProcessCommandLine has_any ("proxy-server","load-extension","disable-extensions-except","remote-debugging","user-data-dir")
| project Timestamp, DeviceName, AccountName, FileName, ProcessCommandLine, SHA256, ReportId),
(DeviceFileEvents
| where Timestamp > ago(14d)
| where SHA256 has_any (BadHashes) or FolderPath has_any ("\\Extensions\\","Chrome\\User Data","Edge\\User Data")
| where FileName in~ ("manifest.json","background.js","service_worker.js","content.js") or SHA256 has_any (BadHashes)
| project Timestamp, DeviceName, InitiatingProcessAccountName, FileName, FolderPath, SHA256, ActionType, ReportId)
| summarize FirstSeen=min(Timestamp), LastSeen=max(Timestamp), Events=count() by DeviceName, InitiatingProcessAccountName, AccountName, InitiatingProcessFileName, FileName, RemoteUrl, RemoteIP, SHA256, FolderPath
| order by LastSeen desc
$ErrorActionPreference = 'SilentlyContinue'
$badHosts = @('api.hhos.ru','de34.rapidstaticserve.cc')
$badHashes = @(
'0fa1d38b9dd7e089db3b47407cb684475e184cd6e0683ec252fe3218f169599c',
'2052a339947490fb10296e6e1f9857a83705a3716a528ed22c65e098b1a593e1',
'29ecbcd44d9e1121c2ba2edad26c214036ab83eeb41f7758e4252ae8f92e3393',
'2a5a967d232d97ff3a4983eefeac69347eaf88d19efdd1e783b2d0268226e894',
'2ebeb17cdbeab7547c8dfebade198739e0f1c5dbf9de2977ce318bfcf132d318',
'3477d7c15ed67ba56295a2a64e525ce3ced65be292b873d154ad2e88de340ae6'
)
$results = New-Object System.Collections.Generic.List[object]
$dnsCache = Get-DnsClientCache | Where-Object { $name = $_.Name; $badHosts | ForEach-Object { $name -like ('*' + $_ + '*') } }
foreach ($d in $dnsCache) { $results.Add([pscustomobject]@{Type='DnsCache'; Host=$env:COMPUTERNAME; User=$env:USERNAME; Indicator=$d.Name; Detail=$d.Entry; Path=''; Hash=''}) }
$net = Get-NetTCPConnection -State Established | Where-Object { $_.RemoteAddress -ne '127.0.0.1' }
foreach ($c in $net) {
try {
$proc = Get-Process -Id $c.OwningProcess
if ($proc.ProcessName -match 'chrome|msedge|firefox') {
$resolved = Resolve-DnsName -Name $badHosts -ErrorAction SilentlyContinue | Select-Object -ExpandProperty IPAddress -ErrorAction SilentlyContinue
if ($resolved -contains $c.RemoteAddress) { $results.Add([pscustomobject]@{Type='Network'; Host=$env:COMPUTERNAME; User=$env:USERNAME; Indicator=$c.RemoteAddress; Detail=$proc.ProcessName + ':' + $c.RemotePort; Path=$proc.Path; Hash=''}) }
}
} catch {}
}
$extRoots = @(
"$env:LOCALAPPDATA\Google\Chrome\User Data",
"$env:LOCALAPPDATA\Microsoft\Edge\User Data"
)
foreach ($root in $extRoots) {
Get-ChildItem -Path $root -Recurse -Filter manifest.json -ErrorAction SilentlyContinue | ForEach-Object {
$mf = $_.FullName
$txt = Get-Content $mf -Raw -ErrorAction SilentlyContinue
if ($txt -match 'proxy|webRequest|webRequestBlocking|cookies|tabs|<all_urls>|declarativeNetRequest|vpn|rutracker|telegram|instagram|chatgpt|netflix|youtube') {
$files = Get-ChildItem -Path (Split-Path $mf) -Recurse -File -ErrorAction SilentlyContinue
foreach ($f in $files) {
$h = (Get-FileHash $f.FullName -Algorithm SHA256).Hash.ToLowerInvariant()
if ($badHashes -contains $h -or $f.Extension -in '.js','.json') {
$results.Add([pscustomobject]@{Type='ExtensionArtifact'; Host=$env:COMPUTERNAME; User=$env:USERNAME; Indicator=$h; Detail=$mf; Path=$f.FullName; Hash=$h})
}
}
}
}
}
$regPath = 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Internet Settings'
$proxy = Get-ItemProperty -Path $regPath
if ($proxy.ProxyEnable -eq 1 -or $proxy.AutoConfigURL -or $proxy.ProxyServer) {
$results.Add([pscustomobject]@{Type='ProxyConfig'; Host=$env:COMPUTERNAME; User=$env:USERNAME; Indicator=$regPath; Detail=('ProxyEnable=' + $proxy.ProxyEnable + '; ProxyServer=' + $proxy.ProxyServer + '; PAC=' + $proxy.AutoConfigURL); Path=''; Hash=''})
}
$results | Sort-Object Type, Detail | Format-Table -AutoSize
$results | Export-Csv -NoTypeInformation -Path "$env:TEMP\fake_vpn_proxyfarm_hunt.csv"
Response Priorities
Immediate: block api.hhos.ru and de34.rapidstaticserve.cc at DNS, proxy, SWG, EDR, and firewall FQDN controls; add all listed SHA256 values to EDR and email/web download blocking; inventory Chrome and Edge extensions by ID, publisher, permission set, and install count; remove or disable extensions requesting proxy, webRequest, cookies, tabs, all URLs, or VPN-like permissions outside an approved allowlist; capture volatile evidence including browser profiles, extension folders, DNS cache, active sockets, and logged-in SaaS sessions before remediation where legally permitted.
24h: because this is browser traffic interception, assume session and credential exposure for affected users. Force password resets for priority users, revoke SSO sessions and refresh tokens, expire OAuth grants for Google, Microsoft, Slack, GitHub, cloud consoles, password managers, and financial apps, require MFA re-registration checks, review impossible travel and token replay alerts, and notify users not to reuse credentials or approve unexpected MFA prompts. Validate whether Chrome Sync propagated extensions to other devices owned by the same user.
1 week: implement browser extension allowlisting through Chrome Enterprise or Edge management, block CRX installs from outside the store, restrict permissions such as proxy and webRequestBlocking, disable user-level PAC changes where not required, enforce browser isolation for high-risk browsing, add canary DNS domains for future config infrastructure, monitor extension update events and publisher reputation, and create a repeatable takedown workflow for lookalike store listings. Feed lessons learned into secure configuration baselines for managed browsers and contractor devices.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.