logo

Kimsuky Using TRANSLATEXT Chrome Extension to Steal Sensitive Data

ID: 110abe2a-e348-5ac5-acfc-d9d502d72691

STIX ID: report--110abe2a-e348-5ac5-acfc-d9d502d72691

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2024-06-28

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

Kimsuky (North Korea-linked APT) deployed a fake Google Translate Chrome extension called TRANSLATEXT to steal emails, credentials, cookies and browser screenshots from South Korean academics; the campaign leveraged spear-phishing, a ZIP/EXE/PowerShell delivery chain, hosted artifacts briefly on GitHub, and has ties to other Kimsuky activity including exploitation of CVE-2017-11882 to deliver backdoors and keyloggers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.