Cyber Security News

North Korean Hackers Uses Malicious Browser Extension To Steal Emails From Chrome

Kimsuky, a North Korean hacker group is believed to be hacking the major web browsers with the help of a malicious browser extension, which intercepts and steals emails.

Researchers at Volexity, who was the first to spot this campaign back in September, named the extension SHARPEXT. There are three different Chromium-based web browsers that this malicious extension is compatible with:-

  • Google Chrome
  • Microsoft Edge
  • Whale

Stealthy Campaign

Moreover, this malicious extension can also steal email from the accounts of Gmail and AOL users. As a result of using a custom VBS script to compromise a target’s system, attackers then install this malicious extension on the system. 

In order to accomplish this, they replace two types of files that we have mentioned below with the files that were downloaded from the malware’s C2 server:-

  • Preferences files
  • Secure Preferences files

In addition to this latest campaign, Kimsuky has also launched similar campaigns in the following countries in which the SHARPEXT has been deployed:-

  • The United States
  • Europe
  • South Korea

Effectual Tactics

This attack can remain undetected as long as the victim’s email provider is not aware that the attacker uses the already-logged-in session of the target to steal emails.

As a result, it becomes extremely difficult to detect it in this way. A suspicious activity alert won’t be triggered on the accounts of victims as a result of the extension’s workflow. 

If you check the webmail account status page for alerts, you will not be able to discover the malicious activity, since the alerts will not be visible.

Illicit Capabilities and Data Collected

There is a wide range of information that could be gathered by North Korean threat actors using SHARPEXT. Here below we have mentioned them:-

  • Make a list of all the emails that have been collected previously from the victim.
  • List email domains with which the victim has previously communicated.
  • Collect a blacklist of email senders.
  • Add a domain to the list of all domains viewed by the victim.
  • Upload a new attachment to the remote server.
  • Upload Gmail data to the remote server.
  • Commented by the attacker; receive an attachments list to be exfiltrated.
  • Upload AOL data to the remote server.

Mitigations

Here below we have mentioned all the recommended mitigations:-

  • Enable PowerShell ScriptBlock logging.
  • Analyze the results of PowerShell ScriptBlock logging.
  • Ensure that all extensions installed on machines of high-risk users are reviewed.
  • For the detection of related activity, you can use the YARA rules.
  • IOCs given should be blocked.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago