The FBI Unplugged 2 Million Hijacked TVs in July. This Week: 737 Fake VPNs That Take Your Connection Because You Asked Them To.
- Patrick Duggan
- 1 day ago
- 5 min read
We have been covering the residential proxy racket for five months, so we want to put three dated events next to each other, because together they describe a supply chain under pressure and an acquisition method moving.
March 12, 2026. The FBI issues advisory PSA260312 on criminal and nation-state abuse of residential proxy networks, without naming one. We published 1,360 indicators against it on April 28.
July 2, 2026. Google's Threat Intelligence Group, the FBI, the IRS and Lumen unplug NetNut — also tracked as Popa — a residential proxy network built on at least two million hijacked home devices. Not servers. Smart TVs and streaming boxes, infected through malicious SDKs the operators baked into ordinary apps. We wrote it up on July 8.
July 22, 2026. LG announces it will ban residential proxy SDKs from webOS, scanning every app in its store for code signatures of known proxy providers and pulling the ones that do not comply. Samsung follows. The trigger was research finding that more than 42 percent of games and apps in LG's own store let unknown third parties route traffic through the customer's television.
August 12, 2026. Socket's Threat Research Team publishes 737 Chrome VPN and proxy extensions funnelling browser traffic through attacker-controlled SOCKS5 infrastructure.
We are not claiming the fourth event is caused by the first three. We have no evidence of that, these extensions almost certainly predate the takedown, and post-hoc causation is exactly the kind of tidy story that turns out wrong. What we will say is narrower and checkable: the device layer is now contested — takedown, platform bans, code-signature scanning — and the browser layer is not.
What the extensions actually do
737 extensions across at least 40 Chrome Web Store developer accounts. 75,486 displayed installs; 516 still live with 58,318 installs when Socket collected them. The targeting is mainly Russian-speaking users trying to reach blocked services — Instagram, ChatGPT, YouTube.
Of 522 packages collected in bulk, 520 configured Chrome to route through the same SOCKS5 infrastructure on port 1082. One port, one shared backend, five hundred storefronts.
Then the detail that matters most, and the one to check your own fleet against: the proxy bypass list in these extensions contains only loopback addresses. Not the corporate domains. Not banking. Not anything. Once the user clicks connect, every request that is not going to 127.0.0.1 goes through the operator.
That puts them in adversary-in-the-middle position over the whole browser session — able to observe destination hosts, TLS SNI, source IP, and the full contents of any unencrypted HTTP. This is not IP borrowing. This is the session.
The inversion, which is the actual story
NetNut took two million connections without asking anyone. A malicious SDK inside a free game on a television, and a stranger's traffic exits your address while you watch a film.
This campaign takes the connection because the user asked for it. 274 of the 737 impersonate 66 established VPN and privacy brands — Proton VPN, NordVPN, Surfshark, ExpressVPN, AdGuard, CyberGhost, Windscribe, TunnelBear, Cloudflare's 1.1.1.1, Google's Outline, AmneziaVPN, AntiZapret.
Read that list again. Those are not random popular apps. Those are the tools people install specifically because they do not want an intermediary reading their traffic. The impersonation targets the exact population that has already decided intermediaries are the threat, and then makes itself the intermediary. Consent is not just obtained — it is obtained by wearing the costume of the thing that promised consent would be respected.
And it is a fair trade from the operator's side: hijacking a TV gets you an IP address. Impersonating a VPN gets you an IP address and the plaintext.
The evasion detail nobody is leading with
A subset of 104 extensions resolve their own proxy hostnames using Cloudflare or Google DNS-over-HTTPS, then hand Chrome the resulting raw IP address.
That is specifically engineered to defeat DNS-layer blocking. The local system never emits a plaintext DNS query for the campaign's domains, so your Pi-hole does not see it, your corporate resolver does not see it, your DNS blocklist does not fire — including ours. The lookup happens inside an encrypted request to a resolver you almost certainly allow, and the extension supplies Chrome with an address instead of a name.
We publish a DNS blocklist. We are telling you it would not have caught these, and why. A DNS-layer control is worth having and it is not a control against an application that carries its own resolver. What catches this is extension inventory and egress: a browser making SOCKS5 connections to port 1082 on an unfamiliar host is visible at the network layer no matter how the name was resolved.
What we had, honestly
On the device layer, we have real receipts and they are dated: 1,360 indicators published April 28, more than two months before the July 2 takedown of the network they belonged to.
On this campaign, we have nothing. We hold no extension IDs and no proxy infrastructure addresses for it, because the disclosure is hours old and the secondary reporting does not carry the IP set. If we had checked our index and found the SOCKS5 backend already in it, that would be a receipt worth showing you. We checked. It is not there to check yet — the identifiers have not been published in the coverage we can reach.
So: credit is Socket's, entirely. Our contribution here is the sequence, the inversion, and the DoH point above.
What to do this afternoon
Inventory browser extensions with proxy permissions. Not "do we allow extensions" — specifically which ones hold the proxy permission, which is the one that lets an extension reconfigure where every request goes. In most environments the correct number of VPN extensions is zero, because the VPN belongs at the endpoint, not in the browser.
Alert on outbound SOCKS5, especially port 1082. It is a specific, cheap, high-signal detection and it survives the DoH trick entirely.
Treat brand impersonation in an official store as expected, not exceptional. 274 fakes of 66 real privacy brands got through review. "It was in the Chrome Web Store" is a statement about distribution, not vetting.
And if you run smart TVs anywhere in your estate — hospitality, waiting rooms, digital signage, break rooms — the July research finding that over 42 percent of one vendor's app store shipped traffic-sharing code is the number to carry into that conversation. LG and Samsung are fixing their stores. Nobody is fixing the TVs already on your wall.
Ninety-five percent, as ever. If the extension infrastructure turns out to overlap indicators we already hold, we will say so and show the timestamps either way.
Every indicator in this post is in the feed. Free.
1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.
Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=the-fbi-unplugged-2-million-hijacked-tvs-in-july-this-week-737-fake-vpns-that-take-your-connection




Comments