HomeSecurityKimsuky hackers use malicious Chrome extension to steal credentials

Kimsuky hackers use malicious Chrome extension to steal credentials

North Korean hackers Kimsuky have been linked to the use of a new malicious Google Chrome extension (codenamed TRANSLATEXT), designed to steal sensitive information.

Kimsuky hackers Chrome extension TRANSLATEXT

Zscaler ThreatLabz detected the malicious activity in early March 2024 and observed that the extension collects email, usernames, passwords, cookies, and takes screenshots.

With the new attacks, the Kimsuky hackers are targeting the South Korean academic community, and especially experts who focus on North Korean political affairs.

See also: Kimsuky hackers target users via Facebook Messenger

Kimsuky is a well-known hacking group from North Korea that has been active since at least 2012. It has been linked to several cyberespionage targeting South Korean entities.

In recent weeks, the group has been exploiting a vulnerability in Microsoft Office (CVE-2017-11882) to distribute a keylogger. They have also used baits related to supposed job openings to target aerospace and defense and steal information.

Cybersecurity firm CyberArmor observed the use of a new backdoor, which allows North Korean hackers Kimsuky to perform basic reconnaissance and install additional payloads to take over or remotely control the machine.

The exact method of initial access is unknown, although the group typically performs spear-phishing and social engineering attacks to trigger the infection chain.

See also: Kimsuky team develops new Linux backdoor Gomir

The starting point of the attack is a ZIP file that supposedly concerns Korean military history and contains two files: a Hangul text editing document and an executable file.

Launching the executable file leads to the retrieval of a PowerShell script from an attacker's server, which, in turn, extracts information about the compromised victim (to a GitHub repository) and downloads additional PowerShell code via a Windows shortcut (LNK) file.

Zscaler said it found the GitHub and saw that it briefly hosted the TRANSLATEXT extension under the name “GoogleTranslate.crx.”

These files were present in the repository on March 7, 2024, and were deleted the next day, suggesting that the Kimsuky hackers intended to minimize exposure and use the malware for a short period of time to target specific individuals,” said security researcher Seongsu Park.

The malicious Chrome extension, TRANSLATEXT, disguised as Google Translate, embeds JavaScript code to bypass security measures for services like Google, Kakao, and Naver. It steals email addresses, credentials, and cookies, while also taking screenshots.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Kimsuky hackers use malicious Chrome extension to steal credentials

One of the primary goals of the Kimsuky group is to monitor academic and government personnel in order to gather valuable information,” Park said.

See also: Kimsuky hackers target crypto companies with Durian malware

This recent development serves as a reminder of the ever- evolving nature of cyber threats, especially from state actors like North Korean hackers Kimsuky. These threat actors are constantly adapting their techniques to remain undetected and collect sensitive information for political or economic gain.

To protect against these types of threats, users and organizations should stay informed about current threats and take protective measures, including keeping software up to date. Additionally, being cautious when downloading extensions from unknown sources can help prevent attacks.

It is also important for governments and organizations to work together to share information about threats and implement strong security protocols.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS