2vk
2vk is a threat actor identified by researchers primarily via the GitHub username/alias “2vk,” linked to a large-scale malicious Google Chrome extension campaign targeting VKontakte (VK) users. The campaign (codenamed “VK Styles”) used Chrome extensions masquerading as VK customization/theme tools to hijack authenticated VK sessions and take over accounts at scale (reported as >500,000 victims; one extension “VK Styles” reportedly reached ~400,000 installs before removal). The malware’s behaviors included forced auto-subscription of victims to attacker-controlled VK groups (used to build a follower base reaching millions), periodic resetting of victim account settings (every ~30 days), and manipulation of VK security mechanisms (including CSRF token/cookie manipulation) to perform unauthorized actions and maintain persistent control. The operation leveraged VK itself as part of its infrastructure to complicate detection and blocking: extensions used an attacker-controlled VK profile (reported as vk[.]com/m0nda) as a dead-drop resolver by reading payload URLs from HTML metadata tags, then fetched and executed next-stage code from a public GitHub repository controlled by 2vk (reported repository name “-”, with a file “C” showing commits from June 2025 through January 2026). The next-stage payload was described as obfuscated JavaScript injected into VK pages, enabling ongoing updates and iterative refinement without republishing the extension package. Targeting was reported to primarily affect Russian-speaking users, with additional impact across Eastern Europe, Central Asia, and Russian diaspora communities worldwide. Activity was assessed as active since at least June 22, 2025 and persisted through January 2026.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Where they target
Geographies tied to known operations.
- 🇷🇺 Russia
Tradecraft
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
1 malware family attributed to this actor across reporting.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operated a malicious Chrome-extension campaign masquerading as VKontakte customization tools (e.g., theme changers) to hijack VK accounts at scale (~500k installs). The extensions abused authenticated VK sessions to take over accounts, force-subscribe victims to attacker-controlled groups to amplify reach, reset user settings periodically, and silently auto-update to push new malicious code. Also monetized via paid theme/features while continuing account abuse.
Operates a large-scale malicious Chrome extension campaign targeting VKontakte users. The extensions masquerade as VK customization tools (e.g., 'VK Styles') and perform account takeover behaviors: persistent code injection on VK pages, retrieval of instructions from attacker-controlled VK profile metadata (used as C2), downloading/execing additional payloads from an attacker-controlled GitHub repo, manipulating VK CSRF cookies/tokens to automate unauthorized actions, and forcing victims to subscribe to attacker-controlled VK groups to aid propagation. Activity described as continuous from June 2025 through January 2026 with iterative development via GitHub commits.
Runs the “VK Styles” malicious-extension campaign that hijacks VKontakte accounts at scale via Chrome extensions masquerading as VK customization/music tools; uses injected/obfuscated JavaScript to manipulate accounts (forced group subscriptions, settings resets), bypass protections via CSRF token manipulation, and maintain persistence; uses GitHub-hosted next-stage payloads and a VK profile metadata dead-drop resolver for C2/payload URL indirection.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.