Over half a million VKontakte accounts hijacked using malicious Chrome extensions

(Image credit: Lesterman/Shutterstock)

Sign up for our newsletter


  • Koi Security Revealed Malware Campaign That Hijacked 500,000+ VKontakte Accounts Via Chrome Extensions
  • Victims automatically subscribing to attacker’s VK group add-ons (1.4 million members), manipulated CSRF tokens, inserted ads, and stole payment data
  • Campaign running since mid-2025, maintained by threat actor “2vk”, primarily targeting Russian-speaking users

Over half a million VKontakte accounts were hijacked in a malware campaign originating from the Google Chrome Web Store.

The campaign was discovered by researchers from Koi Security and included five extensions advertised as an improvement to the platform.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top