logo

SharpTongue Deploys Clever Mail-Stealing Browser Extension “SHARPEXT”

ID: ab594fc6-2b9f-5a5b-ac0d-ce5c5701478c

STIX ID: report--ab594fc6-2b9f-5a5b-ac0d-ce5c5701478c

Feed Name: Volexity Blog

Threat Score
88/100

Date Published: 2022-07-28

Date Updated: 2026-05-01

...
...

Volexity documents SharpTongue (Kimsuky) deploying a malicious Chromium-based browser extension called SHARPEXT to exfiltrate email and attachments from victims' Gmail and AOL webmail sessions. The attacker manually harvests and replaces users' Secure Preferences to install the extension, uses PowerShell to enable and hide DevTools, and loads most logic from a C2 to avoid detection; Volexity observed multiple incidents with thousands of emails stolen and provides IOCs, YARA rules, and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.