Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
1 malware family

2vk

Also known as2vk

2vk is a threat actor identified by researchers primarily via the GitHub username/alias “2vk,” linked to a large-scale malicious Google Chrome extension campaign targeting VKontakte (VK) users. The campaign (codenamed “VK Styles”) used Chrome extensions masquerading as VK customization/theme tools to hijack authenticated VK sessions and take over accounts at scale (reported as >500,000 victims; one extension “VK Styles” reportedly reached ~400,000 installs before removal). The malware’s behaviors included forced auto-subscription of victims to attacker-controlled VK groups (used to build a follower base reaching millions), periodic resetting of victim account settings (every ~30 days), and manipulation of VK security mechanisms (including CSRF token/cookie manipulation) to perform unauthorized actions and maintain persistent control. The operation leveraged VK itself as part of its infrastructure to complicate detection and blocking: extensions used an attacker-controlled VK profile (reported as vk[.]com/m0nda) as a dead-drop resolver by reading payload URLs from HTML metadata tags, then fetched and executed next-stage code from a public GitHub repository controlled by 2vk (reported repository name “-”, with a file “C” showing commits from June 2025 through January 2026). The next-stage payload was described as obfuscated JavaScript injected into VK pages, enabling ongoing updates and iterative refinement without republishing the extension package. Targeting was reported to primarily affect Russian-speaking users, with additional impact across Eastern Europe, Central Asia, and Russian diaspora communities worldwide. Activity was assessed as active since at least June 22, 2025 and persisted through January 2026.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Where they target

Geographies tied to known operations.

  • 🇷🇺 Russia
MITRE ATT&CK

Tradecraft

6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

7 of 15 tactics8 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0002
Execution
2 techniques
T1072
Software Deployment Tools
T1204
User Execution
TA0003
Persistence
1 technique
T1098
Account Manipulation
TA0004
Privilege Escalation
1 technique
T1098
Account Manipulation
TA0005
Stealth
1 technique
T1027
Obfuscated Files or Information
TA0008
Lateral Movement
1 technique
T1072
Software Deployment Tools
TA0009
Collection
1 technique
T1213
Data from Information Repositories
TA0011
Command and Control
1 technique
T1102
Web Service
ACTIVITY FEED

Recent activity

3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

the record mediaNews
Feb 16, 2026
Over 500,000 VKontakte accounts hijacked through malicious Chrome extensions | The Record from Recorded Future News

Operated a malicious Chrome-extension campaign masquerading as VKontakte customization tools (e.g., theme changers) to hijack VK accounts at scale (~500k installs). The extensions abused authenticated VK sessions to take over accounts, force-subscribe victims to attacker-controlled groups to amplify reach, reset user settings periodically, and silently auto-update to push new malicious code. Also monetized via paid theme/features while continuing account abuse.

Read more
cyber security newsNews
Feb 13, 2026
Chrome Extensions Infected 500K Users to Hijack VKontakte Accounts

Operates a large-scale malicious Chrome extension campaign targeting VKontakte users. The extensions masquerade as VK customization tools (e.g., 'VK Styles') and perform account takeover behaviors: persistent code injection on VK pages, retrieval of instructions from attacker-controlled VK profile metadata (used as C2), downloading/execing additional payloads from an attacker-controlled GitHub repo, manipulating VK CSRF cookies/tokens to automate unauthorized actions, and forcing victims to subscribe to attacker-controlled VK groups to aid propagation. Activity described as continuous from June 2025 through January 2026 with iterative development via GitHub commits.

Read more
the hacker newsNews
Feb 13, 2026
Malicious Chrome Extensions Caught Stealing Business Data, Emails, and Browsing History

Runs the “VK Styles” malicious-extension campaign that hijacks VKontakte accounts at scale via Chrome extensions masquerading as VK customization/music tools; uses injected/obfuscated JavaScript to manipulate accounts (forced group subscriptions, settings resets), bypass protections via CSRF token manipulation, and maintain persistence; uses GitHub-hosted next-stage payloads and a VK profile metadata dead-drop resolver for C2/payload URL indirection.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping6

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal1

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.