{"id":6281,"date":"2025-08-20T10:04:25","date_gmt":"2025-08-20T10:04:25","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/08\/20\/legitimate-chrome-vpn-with-100000-installs-silently-captures-screenshots-and-exfiltrate-sensitive-data\/"},"modified":"2025-08-20T10:04:25","modified_gmt":"2025-08-20T10:04:25","slug":"legitimate-chrome-vpn-with-100000-installs-silently-captures-screenshots-and-exfiltrate-sensitive-data","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/08\/20\/legitimate-chrome-vpn-with-100000-installs-silently-captures-screenshots-and-exfiltrate-sensitive-data\/","title":{"rendered":"Legitimate Chrome VPN With 100,000+ Installs Silently Captures Screenshots and Exfiltrate Sensitive Data"},"content":{"rendered":"<p>    Legitimate Chrome VPN With 100,000+ Installs Silently Captures Screenshots and Exfiltrate Sensitive Data<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A Chrome VPN extension with over 100,000 installations and verified badge status has been discovered operating as sophisticated spyware, continuously capturing user screenshots and exfiltrating sensitive data without consent.<\/p>\n<p>The extension, known as FreeVPN.One, masqueraded as a legitimate privacy tool while secretly implementing comprehensive surveillance capabilities that directly contradict its stated privacy promises.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhsPYqyhHuRWPKY7cJ-l02ARc89svuwex6utvNsHdwDVM6dT43uoRAbuow-O3wNNmU5Z94hvY_6A6qKIcLPNB4gXMO2ydvnXT1CfVaetZ7WzN_QZLiEio7RvO4u1F8QzX_MRmdOAvUtNDiHEchSf0OzC1KBUr0u3QXHfVDOiWP5Cfa_WczW7NrByrPzJQU\/s16000\/FreeVPN.One%25E2%2580%258A%25E2%2580%2594%25E2%2580%258Afeatured%2C%2520verified%2C%2520and%2520spyware%2520%28Source%2520-%2520Koi.Security%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">FreeVPN.One\u200a\u2014\u200afeatured, verified, and spyware (Source \u2013 Koi.Security)<\/figcaption><\/figure>\n<\/div>\n<p>The malicious extension gained prominence through Google\u2019s Chrome Web Store, achieving featured placement and verified status despite implementing backdoor functionality that captures screenshots of every webpage users visit.<\/p>\n<p>Operating under the guise of providing privacy protection, the extension employs a deceptive two-stage architecture that silently monitors user activity across all browsing sessions, capturing sensitive information including banking credentials, personal communications, and private documents.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg5zsmsIIjTFNbdThSb9yekiRAwuBYZ77EJUQZymK9vdAtCEuurpOfFgwO3Yp0zYbkBJEqlmKOSrurRDElJllkM8t3FEBi_p0cjc_NnsHwBJuOBuItC86DnuAaHqm8xd9NLT03usWTvRIzQWgYR2QpdVqY7wPY1Uya3pM_wkZKibMEB9VvwbzFWguWxqHo\/s16000\/Private%2520pictures%2520sent%2520to%2520the%2520spyware%25E2%2580%2599s%2520backend%2520%28Source%2520-%2520Koi.Security%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Private pictures sent to the spyware\u2019s backend (Source \u2013 Koi.Security)<\/figcaption><\/figure>\n<\/div>\n<p>Koi.Security analysts <a href=\"https:\/\/www.koi.security\/blog\/spyvpn-the-vpn-that-secretly-captures-your-screen\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">noted<\/a> that the extension\u2019s evolution from legitimate VPN service to spyware occurred through a series of calculated updates beginning in April 2025, when developers introduced broad permissions that enabled comprehensive data collection capabilities.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgwgKJh4VqL3U8VkRwrEO9a25i__dmQBOl6F3sojjAUVh97HZ7_yPH6bQzgDVZTWKkrBjspLhJrVYyDAwSY8YhUppT9Op4va9AYMsIp9nxXK8PWcGfVNfv4xDyTMmrKGdY03Bdyjv-tCKvihC9ZADWJMvpNeZrjriMHCOKS-IroECd5DxVFTFIPHjmmEuc\/s16000\/DevTools%2520showing%2520captured%2520Google%2520Sheets%2520tab%2520with%2520sensitive%2520data%2520%28Source%2520-%2520Koi.Security%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">DevTools showing captured Google Sheets tab with sensitive data (Source \u2013 Koi.Security)<\/figcaption><\/figure>\n<\/div>\n<p>Security researchers identified the transformation as particularly concerning, given the extension\u2019s verified status and widespread adoption among privacy-conscious users.<\/p>\n<p>The <a href=\"https:\/\/cybersecuritynews.com\/smarter-security-how-modern-surveillance-improves-business-decisions\/\" target=\"_blank\" rel=\"noreferrer noopener\">surveillance<\/a> campaign impacts users globally, with captured screenshots containing sensitive corporate data, financial information, and personal communications being transmitted to remote servers controlled by the threat actors.<\/p>\n<p>The extension\u2019s privileged position within users\u2019 browsers enables unrestricted access to all browsing activity, creating a comprehensive intelligence-gathering operation that operates entirely without user knowledge or consent.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-technical-implementation-and-evasion-mechanisms\"><strong>Technical Implementation and Evasion Mechanisms<\/strong><\/h2>\n<p>The extension implements its surveillance capabilities through a sophisticated content script injection system that automatically deploys across all HTTP and HTTPS websites using the broad <code>matches: [\"http:\/\/*\/*\", \"https:\/\/*\/*\"]<\/code> pattern.<\/p>\n<p>Upon page load initialization, the malicious code executes a precisely timed delay mechanism:-<\/p>\n<pre class=\"wp-block-code\"><code>setTimeout(() =&gt; {\n    chrome.runtime.sendMessage({action: 'captureViewport'});\n}, 1100);<\/code><\/pre>\n<p>This code waits exactly 1.1 seconds after page initialization before triggering screenshot capture, ensuring complete page rendering for maximum data quality.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjb8VEVg-o2gPwwNdbnIPPAZoVAJSnH0DTmAL_Hxsxd8c60xl9r2UTJMFYX1zXmx4ZQHszwoOEnjYQ4iX0tNCx-V5q5SdbpP7Yj3EepEQruKXRbMatmcz2IqLhrKtzFweAZlx0RIZKZZYWSdxi27EKHYA2pHxEFYls8-yzmFjSRpaNT6wI34RLjXIYGuEw\/s16000\/%27Scan%2520with%2520AI%27%2520click%2520redirect%2520to%2520aitd%255B.%255Done%2520site%2520%28Source%2520-%2520Koi.Security%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">\u2018Scan with AI\u2019 click redirect to aitd[.]one site (Source \u2013 Koi.Security)<\/figcaption><\/figure>\n<\/div>\n<p>The background service worker receives the captureViewport message and executes actual screenshot capture using Chrome\u2019s privileged <code>chrome.tabs.captureVisibleTab()<\/code> API, automatically transmitting captured images to <code>aitd[.]one\/brange.php<\/code> alongside page URLs, tab identifiers, and unique user tracking codes.<\/p>\n<p>Recent versions implement AES-256-GCM encryption with RSA key wrapping to <a href=\"https:\/\/cybersecuritynews.com\/researchers-obfuscated-weaponized-net-assemblies\/\" target=\"_blank\" rel=\"noreferrer noopener\">obfuscate<\/a> data transmission, making network-based detection significantly more challenging.<\/p>\n<p>The encryption layer masks the continuous screenshot exfiltration while maintaining the extension\u2019s surveillance capabilities, demonstrating the threat actors\u2019 commitment to <a href=\"https:\/\/cybersecuritynews.com\/malware-persistence-mechanisms-used-by-hackers\/\" target=\"_blank\" rel=\"noreferrer noopener\">persistence<\/a> and detection evasion.<\/p>\n<p>The extension\u2019s permission structure requires <code>&lt;all_urls&gt;<\/code>, <code>tabs<\/code>, and <code>scripting<\/code> permissions, creating a comprehensive surveillance framework that extends far beyond legitimate <a href=\"https:\/\/cybersecuritynews.com\/vpn-service-provider-hacker-supply-chain-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">VPN<\/a> functionality requirements and enables complete user activity monitoring.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong><code>Boost\u00a0your\u00a0SOC and help your team protect your business with free top-notch threat intelligence:\u00a0<a href=\"https:\/\/intelligence.any.run\/plans\/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=alert_fatigue&amp;utm_content=lookup_plan&amp;utm_term=120825\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Request TI Lookup Premium Trial<\/a>.<\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/legitimate-chrome-vpn\/\">Legitimate Chrome VPN With 100,000+ Installs Silently Captures Screenshots and Exfiltrate Sensitive Data<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/legitimate-chrome-vpn\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Legitimate Chrome VPN With 100,000+ Installs Silently Captures Screenshots and Exfiltrate Sensitive Data A Chrome VPN extension with over 100,000 installations and verified badge status has been discovered operating as sophisticated spyware, continuously capturing user screenshots and exfiltrating sensitive data without consent. The extension, known as FreeVPN.One, masqueraded as a legitimate privacy tool while secretly [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-6281","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6281"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6281"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6281\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6281"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6281"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6281"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}