Threat reportMalwareTL-2026-1198
Malicious 'Free VPN' Chrome and Firefox Extensions (VPN Go) Deploy Clipboard-Stealing Malware via Trojanized Updates
Malicious 'Free VPN' Chrome and Firefox Extensions (VPN Go) (TL-2026-1198), also tracked as VPN Go Clipboard Stealer, is a high-severity malware campaign, first published 2026-07-10. It has no confirmed attribution, affects Unknown (self-published, developer alias zegivati83) VPN Go: Free VPN, maps to 16 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 20 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 16MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 20Indicators of compromise
Key facts for TL-2026-1198
- Threat ID
- TL-2026-1198
- Also known as
- VPN Go Clipboard Stealer, Free VPN Clipboard Exfiltration Campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- all sectors general consumer enterprise browser users
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 20
How Malicious 'Free VPN' Chrome and Firefox Extensions (VPN Go) works
Socket.dev researchers discovered that "VPN Go: Free VPN" (Chrome, 146 users) and "Free VPN by VPN GO" (Firefox, 3,499 users) shipped legitimate proxy functionality for months before malicious updates added clipboard-monitoring code that chunks and exfiltrates copied text via HTTP GET requests to attacker-controlled servers. Both extensions were reported to Google and Mozilla and have since been removed.
Beginning December 22, 2025, a developer using the alias "zegivati83" (zegivati83@gmail.com) published "VPN Go: Free VPN" to the Chrome Web Store and a companion "Free VPN by VPN GO" (internal manifest name "VPN Go", Gecko ID vpngo@vpngo.com) to Mozilla Add-ons. Both extensions functioned purely as free proxy/VPN tools through their initial release versions, building a trusted user base of 146 (Chrome) and 3,499 (Firefox) installs.
The threat actor weaponized the extensions through ordinary-looking auto-updates rather than at initial publication, evading store review scrutiny that typically focuses on submission time. Chrome version 1.1 (published May 31, 2026) added the clipboardRead permission and a content script (scripts/version.js) injected into every visited page (host permissions <all_urls>), polling navigator.clipboard.readText() every 500ms and deduplicating against the last-seen value to avoid redundant exfiltration. A background script (scripts/background.js) handled the runtime messaging and outbound HTTP delivery. Firefox's malicious functionality first appeared in version 1.3.3, consolidated into a single background script polling at a slower 1.5-second interval.
Stolen clipboard text is split into ~1,000-character chunks (exact size randomized via 1000 + Math.floor(19 * Math.random()) to reduce pattern-matching signature reliability), tagged with a base36 timestamp-derived session identifier (uid), and sent as HTTP GET requests using fetch() with mode: 'no-cors' — a technique that suppresses CORS errors in the browser console and lets the request fire-and-forget without the extension needing to read a response, minimizing forensic footprint in dev tools. Query parameters carry uid (session), part (chunk index), total (chunk count), and data (the stolen text fragment) to a PHP receiver at /html/continue.php on attacker infrastructure, authenticated with a static bearer token embedded in the extension code. The same infrastructure also served the extension's proxy backend (/locations endpoint), giving the operators a legitimate-looking dual-purpose C2 channel that blends malicious exfiltration traffic with expected VPN proxy traffic.
Infrastructure rotated at least twice: Chrome v1.1-1.2 and Firefox v1.3.3 used 178.236.252.133 (Firefox on a distinct but adjacent host, 178.236.252.161); Chrome v1.3 and Firefox v1.3.4 migrated in tandem to 77.91.123.187 on June 14, 2026, indicating shared operational control and synchronized infrastructure management across both browser variants. Code-level obfuscation included meaningless variable names, escaped property-access strings, arithmetic-derived constants (e.g., deriving an IP octet via 154 / 2 = 77), and URL fragment reassembly from split string components — techniques intended to defeat static string-matching detection by store reviewers and security scanners.
Because clipboard contents routinely include passwords, MFA/TOTP codes, API keys, OAuth tokens, cloud credentials, cryptocurrency wallet addresses, and seed/recovery phrases, this campaign represents a high-value, low-noise credential and secrets harvesting operation disguised as a privacy tool. The extensions' own privacy policy — hosted on Telegraph (telegra.ph/Privacy-Policy-12-11-127) under contact info@vpngogmail.com — explicitly claimed the product "does not collect, store, or process any personal data," directly contradicted by the implemented clipboard theft, indicating premeditated deception rather than accidental telemetry overreach. Socket reported both extensions to Google and Mozilla; both listings have been pulled from their respective stores as of disclosure.
MITRE ATT&CK techniques used in TL-2026-1198
Collection
T1005 Data from Local System; T1115 Clipboard Data; T1119 Automated Collection
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1059.007 JavaScript; T1204 User Execution
Command and Control
T1071.001 Web Protocols; T1105 Ingress Tool Transfer; T1571 Non-Standard Port
Persistence
Initial Access
T1189 Drive-by Compromise; T1195 Supply Chain Compromise
Discovery
Credential Access
Affected products and versions in Malicious 'Free VPN' Chrome and Firefox Extensions (VPN Go)
- Unknown (self-published, developer alias zegivati83) — VPN Go: Free VPN (Chrome Web Store extension)
Vulnerable versions: 1.1; 1.2; 1.3
Fixed in: removed from Chrome Web Store - Unknown (self-published, developer alias zegivati83) — Free VPN by VPN GO (Firefox Add-on, manifest name 'VPN Go')
Vulnerable versions: 1.3.3; 1.3.4
Fixed in: removed from Mozilla Add-ons
Remediation for Malicious 'Free VPN' Chrome and Firefox Extensions (VPN Go)
Immediate actions
- Remove 'VPN Go: Free VPN' (Chrome extension ID jgpfgonjjolillilkjfkiddakagkkpoj) and 'Free VPN by VPN GO' (Firefox, Gecko ID vpngo@vpngo.com) from all endpoints immediately
- Rotate any credentials, API keys, OAuth tokens, or secrets that were copied to the clipboard on an affected device since May 31, 2026 (Chrome) or the Firefox v1.3.3 release date
- Block outbound traffic to 178.236.252.133, 178.236.252.161, and 77.91.123.187 at the network perimeter and DNS/proxy layer
- Audit browser extension inventories org-wide for the malicious extension IDs and associated file hashes
- Review clipboard-monitoring alerts or DLP logs for cryptocurrency wallet address or credential-pattern exfiltration during the exposure window
Workarounds
- Disable browser extension auto-updates and require manual review of new extension versions before deployment in managed fleets
- Use OS-level clipboard managers with limited history/expiry to reduce the window sensitive data remains readable by extensions
Longer-term hardening
- Enforce browser extension allowlisting via enterprise policy (Chrome ExtensionInstallAllowlist / Firefox ExtensionSettings) rather than permitting unrestricted Web Store/AMO installs
- Deploy extension risk-scanning tooling (e.g., Socket, CRXcavator) to continuously re-scan installed extensions after every auto-update, not just at install time
- Restrict or monitor the clipboardRead permission via enterprise extension policy given its high abuse potential for credential/secret theft
- Educate users that free VPN/proxy browser extensions are a recurring vector for credential-harvesting supply-chain attacks and should be sourced only from vetted vendors
Weaknesses (CWE) in Malicious 'Free VPN' Chrome and Firefox Extensions (VPN Go)
Timeline of Malicious 'Free VPN' Chrome and Firefox Extensions (VPN Go)
- "VPN Go: Free VPN" v1.0 published to the Chrome Web Store as a legitimate proxy-only extension
- Chrome v1.1 published, adding the clipboardRead permission and a content script (scripts/version.js) that polls the clipboard every 500ms and begins exfiltration to 178.236.252.133
- Firefox "Free VPN by VPN GO" v1.3.3 introduces clipboard monitoring (1.5-second polling) and exfiltration to 178.236.252.161, after versions 1.1-1.3.2 were proxy-only
- Chrome v1.2 published, preserving clipboard theft functionality against the same 178.236.252.133 infrastructure
- Chrome v1.3 and Firefox v1.3.4 migrate exfiltration infrastructure in tandem to 77.91.123.187, indicating coordinated operational control across both browser variants
- Both extensions removed from the Chrome Web Store and Mozilla Add-ons following Socket's disclosure
- CyberInsider, TechRadar, and other outlets republish and corroborate Socket's findings
- Socket reports both extensions to Google and Mozilla for review and removal
- Socket.dev publishes research disclosing the clipboard-stealing behavior in both extensions, reporting Chrome had 146 active users and Firefox had 3,499
Sources cited for Malicious 'Free VPN' Chrome and Firefox Extensions (VPN Go)
- Chrome and Firefox extensions for free VPNs add clipboard stealers
- Chrome and Firefox Free VPN extensions caught stealing clipboard data
- That free VPN Chrome and Firefox extension may be reading your clipboard every half a second, researchers warn
- Chrome and Firefox Extensions Posing as Free VPNs Add Clipboard Stealers via Malicious Updates
- Malicious Chrome Extensions as VPN Intercept User Traffic to Steal Credentials
Detection coverage for TL-2026-1198
As of 2026-07-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1198 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.