Kimsuky, a North Korean hacker group is believed to be hacking the major web browsers with the help of a malicious browser extension, which intercepts and steals emails.
Researchers at Volexity, who was the first to spot this campaign back in September, named the extension SHARPEXT. There are three different Chromium-based web browsers that this malicious extension is compatible with:-
Moreover, this malicious extension can also steal email from the accounts of Gmail and AOL users. As a result of using a custom VBS script to compromise a target’s system, attackers then install this malicious extension on the system.
In order to accomplish this, they replace two types of files that we have mentioned below with the files that were downloaded from the malware’s C2 server:-
In addition to this latest campaign, Kimsuky has also launched similar campaigns in the following countries in which the SHARPEXT has been deployed:-
This attack can remain undetected as long as the victim’s email provider is not aware that the attacker uses the already-logged-in session of the target to steal emails.
As a result, it becomes extremely difficult to detect it in this way. A suspicious activity alert won’t be triggered on the accounts of victims as a result of the extension’s workflow.
If you check the webmail account status page for alerts, you will not be able to discover the malicious activity, since the alerts will not be visible.
Illicit Capabilities and Data Collected
There is a wide range of information that could be gathered by North Korean threat actors using SHARPEXT. Here below we have mentioned them:-
Mitigations
Here below we have mentioned all the recommended mitigations:-
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates.
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…