• News/
  • https://www.bleepingcomputer.com/news/security/data-stealing-chrome-extensions-impersonate-fortinet-youtube-vpns/

Data-stealing Chrome extensions impersonate Fortinet, YouTube, VPNs

BleepingComputer
·
Bill Toulas
·
Published May 21, 2025
·
Updated

A Google Chrome Web Store campaign uses over 100 malicious browser extensions that mimic legitimate tools, such as VPNs, AI assistants, and crypto utilities, to steal browser cookies and execute remote scripts secretly. The extensions offer some of the promised functionality, but also connect to the threat actor's infrastructure to steal user information or receive commands to execute. Additionally, the malicious Chrome extensions can modify network traffic to deliver ads, perform redirections, or proxying. The campaign was discovered by security researchers at DomainTools, who spotted over 100 fake domains promoting the tools to unsuspecting users, likely through malvertising. DomainTools' list of over 100 malicious websites includes multiple fake VPN brands as well as attempts to impersonate legitimate brands, such as Fortinet, YouTube, DeepSeek AI, and Calendly: These websites include "Add to Chrome" buttons that link to malicious browser extensions on the Chrome Web Store, thus increasing the sense of legitimacy. Although Google removed many of the extensions DomainTools identified, BleepingComputer has confirmed that some remain on the Chrome Web Store. "The Chrome Web Store has removed multiple of the actor's malicious extensions after malware identification," explain the researchers. "However, the actor's persistence and the time lag in detection and removal pose a threat to users seeking productivity tools and browser enhancements." While each extension performs diff...

Read full article

Affected Software

4 affected components
Google Chrome
Fortinet VPN
DeepSeek AI
Google Chrome
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a campaign involving malicious Chrome extensions that impersonate legitimate tools to steal user data.

2

What security implications are discussed in this article?

The security implications include the unauthorized theft of browser cookies and the execution of remote scripts through malicious extensions.

3

What products or software are affected by the malicious extensions?

The affected software includes Google Chrome, Fortinet VPN, and tools impersonated by the extensions such as AI assistants and crypto utilities.

4

How many malicious extensions are involved in this Chrome campaign?

The campaign involves over 100 malicious browser extensions aimed at deceiving users.

5

What methods do these malicious Chrome extensions use to exploit users?

These extensions steal browser cookies and execute scripts secretly without user consent.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203