logo

Over 500,000 VKontakte accounts hijacked through malicious Chrome extensions

ID: 00964cde-74b3-5f27-95a2-8ad5282b95e3

STIX ID: report--00964cde-74b3-5f27-95a2-8ad5282b95e3

Feed Name: The Record from Recorded Future News

Threat Score
78/100

Date Published: 2026-02-16

Date Updated: 2026-05-01

...
...

Cybersecurity researchers uncovered a large-scale malware campaign of five Chrome extensions marketed as VKontakte customization tools that collectively had about 500,000 installs; the extensions hijacked VK accounts, auto-subscribed victims to attacker groups, manipulated settings, recorded payments to unlock features, and silently updated to receive new malicious code. The operation has been linked to a single actor using the GitHub alias "2vk", leveraged VKontakte for infrastructure to evade detection, and was active from mid‑2025 through January 2026 with targets concentrated among Russian-speaking users and diaspora communities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.