Malware, Threat Intelligence

Illicit Chrome extensions facilitate sweeping VKontakte account hack

Laptop Screen Warning Alert: Cyber Attack, Virus, Malware, Spyware, System Hacked

Major Russian social networking service VKontakte had over 500,000 accounts taken over through five malicious Google Chrome extensions masquerading as customization utilities in an attack campaign that ran between mid-2025 and January 2026, reports The Record, a news site by cybersecurity firm Recorded Future.

Installation of the nefarious extensions permitted not only automated subscriptions to attacker-controlled groups and monthly resets of personal settings, but also the abuse of VK security weaknesses for unauthorized activity, according to a report from Koi Security researchers. Threat actor 2vk, who exploited VKontakte for the malware's infrastructure as part of the campaign, was also able to stealthily distribute illicit code through automated extension updates.

Google has already removed one of the malicious extensions, VK Styles, following advice from researchers. Such a development comes more than a month after information-stealing code aimed at AI and VPN tools was discovered to have been embedded in dozens of Chrome extensions, which have amassed almost 2.6 million installations.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds