Over half a million VKontakte accounts hijacked using malicious Chrome extensions


an on a computer Browsing Google
(Image credit: Lesterman / Shutterstock)

Subscribe to our newsletter


  • Koi Security uncovered malware campaign hijacking 500,000+ VKontakte accounts via Chrome extensions
  • Add-ons auto-subscribed victims to attacker’s VK groups (1.4M members), manipulated CSRF tokens, injected ads, and stole payment data
  • Campaign ongoing since mid-2025, maintained by threat actor “2vk,” primarily targeting Russian-speaking users

Over half a million VKontakte accounts were hijacked in a malware campaign which originated on the Google Chrome Web Store.

The campaign was spotted by researchers from Koi Security and included five extensions advertised as an enhancement for the platform.


https://cdn.mos.cms.futurecdn.net/rJVTocga2gNpgdJnVGqpk9-2000-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img