Kimsuky Using TRANSLATEXT Chrome Extension to Steal Sensitive Data
ID: 110abe2a-e348-5ac5-acfc-d9d502d72691
STIX ID: report--110abe2a-e348-5ac5-acfc-d9d502d72691
Feed Name: The Hacker News
Threat Score
Kimsuky (North Korea-linked APT) deployed a fake Google Translate Chrome extension called TRANSLATEXT to steal emails, credentials, cookies and browser screenshots from South Korean academics; the campaign leveraged spear-phishing, a ZIP/EXE/PowerShell delivery chain, hosted artifacts briefly on GitHub, and has ties to other Kimsuky activity including exploitation of CVE-2017-11882 to deliver backdoors and keyloggers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
