<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Proxy on CuraSec</title><link>https://curasec.metacog.co.kr/tags/proxy/</link><description>Recent content in Proxy on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 13 Aug 2026 11:57:16 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/proxy/index.xml" rel="self" type="application/rss+xml"/><item><title>737 fake Chrome VPN extensions route traffic via rogue SOCKS5 proxies</title><link>https://curasec.metacog.co.kr/insights/2026-08-13-hundreds-of-fake-chrome-vpn-extensions-route-traffic-through/</link><pubDate>Thu, 13 Aug 2026 11:57:16 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-13-hundreds-of-fake-chrome-vpn-extensions-route-traffic-through/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Audit any corporate-managed Chrome extensions against a blocklist of the 737 identified fakes; establish a policy requiring allowlisted extensions only for managed devices.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Build detection for unusual SOCKS5 proxy egress from endpoints, and consider hunting for browser extension IDs associated with this campaign in endpoint telemetry.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Illustrates scale of Chrome Web Store supply-chain risk for enterprise endpoints; useful context for policy decisions around browser extension governance, but no immediate board-level action required.&lt;/li>
&lt;/ul></description></item><item><title>737 Malicious Chrome VPN Extensions Proxy User Traffic via Hidden Infrastructure</title><link>https://curasec.metacog.co.kr/insights/2026-08-13-737-chrome-vpn-extensions-caught-routing-traffic-through-pro/</link><pubDate>Thu, 13 Aug 2026 11:57:16 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-13-737-chrome-vpn-extensions-caught-routing-traffic-through-pro/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Extensions impersonating legitimate tools and silently proxying browser traffic is a real enterprise risk if employees install free VPNs on managed Chrome instances. Audit installed extensions across corporate devices and enforce an allowlist policy to block unapproved extensions.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Browser extension-based traffic interception is a useful TTP to understand, but the summary provides no IOCs, C2 infrastructure details, or SIEM/EDR-actionable signals — primarily consumer-targeted with no immediate detection engineering opportunity.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item></channel></rss>