Kimsuky’s Latest Espionage Campaign Targets Gmail via Malicious Chrome Extension
A new cyber espionage campaign attributed to the North Korean threat group Kimsuky has been uncovered, leveraging a malicious Chrome extension to steal Gmail data from victims in South Korea and Japan during the first half of 2026. The operation, identified by researchers at Enki, combines phishing, browser-based theft, and remote access tools to compromise targets.
Attack Chain & Tactics
The campaign begins with phishing emails containing OneDrive sharing links that deliver a Windows shortcut (LNK) file. When opened, the shortcut displays a decoy document while executing hidden commands to download additional malware, establishing a foothold on the victim’s system.
Key components of the attack include:
- Malicious Chrome Extension: Named "Gmail automatic server uploader" (in Korean), the extension monitors Gmail activity, capturing emails, attachments, sender/recipient details, and message content without user awareness. Data is exfiltrated to an attacker-controlled server via encoded transmissions.
- AI-Generated Code: The extension’s JavaScript files contain Korean comments, debugging text, and emojis, suggesting generative AI was used in its development.
- Remote Access Tools: Kimsuky deployed Chrome Remote Desktop (with a UAC bypass for elevated privileges) and AnyDesk (hidden from view) to maintain persistence and full system control.
- Email & Keylogging Theft: Beyond Gmail, the attackers harvested Thunderbird and Outlook emails, logged keystrokes, and conducted system reconnaissance to evade detection.
Evasion & Persistence Techniques
- Rapidly Rotating C2 Servers: Kimsuky abused compromised Korean servers and free Japanese hosting services to obscure infrastructure.
- Scheduled Tasks: A task named Chrome_Update ran every 15 minutes, allowing attackers to update malware post-infection.
- Legitimate Software Abuse: The use of trusted remote-access tools (Chrome Remote Desktop, AnyDesk) complicates detection, as these are often whitelisted in enterprise environments.
Targets & Impact
The campaign focused on South Korean and Japanese individuals, likely in government, research, or policy-related sectors, given the decoy documents’ themes (e.g., "What Did Xi Jinping Do in Pyongyang?"). The multi-stage theft combining browser extensions, email clients, and keyloggers amplifies the risk of credential compromise, intellectual property theft, and long-term surveillance.
Indicators of Compromise (IoCs)
Enki’s report includes file hashes, IP addresses, URLs, and mutexes associated with the campaign. Key IoCs include:
- Malicious LNK files (e.g., "習氏は何をしに平壌に行ったのか.lnk")
- C2 Infrastructure:
103.77.242[.]187,160.187.147[.]119 - Exfiltration Endpoints:
hxxps://sweet-iki-4263.holy[.]jp/gmail.php - Scheduled Tasks:
Chrome_Update,User_Feed_Synchronization-{...}
The operation underscores Kimsuky’s adaptation of AI tools and legitimate software to enhance espionage capabilities while evading traditional defenses.
Source: https://cybersecuritynews.com/kimsuky-ai-generated-chrome-extension/
Google cybersecurity rating report: https://www.rankiteo.com/company/google
"id": "GOO1787581656",
"linkid": "google",
"type": "Cyber Attack",
"date": "1/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': ['Government',
'Research',
'Policy-related Sectors'],
'location': ['South Korea', 'Japan'],
'type': 'Individuals'}],
'attack_vector': ['Phishing',
'Malicious Browser Extension',
'Remote Access Tools'],
'data_breach': {'data_exfiltration': True,
'personally_identifiable_information': True,
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Emails',
'Attachments',
'Sender/Recipient Details',
'Message Content',
'Keystrokes']},
'date_detected': '2026-01-01',
'description': 'A new cyber espionage campaign attributed to the North Korean '
'threat group Kimsuky has been uncovered, leveraging a '
'malicious Chrome extension to steal Gmail data from victims '
'in South Korea and Japan during the first half of 2026. The '
'operation combines phishing, browser-based theft, and remote '
'access tools to compromise targets.',
'impact': {'data_compromised': ['Emails',
'Attachments',
'Sender/Recipient Details',
'Message Content',
'Keystrokes',
'System Reconnaissance Data'],
'identity_theft_risk': 'High',
'operational_impact': 'Long-term surveillance and intellectual '
'property theft',
'systems_affected': ['Gmail',
'Thunderbird',
'Outlook',
'Windows Systems']},
'initial_access_broker': {'backdoors_established': ['Chrome Remote Desktop',
'AnyDesk'],
'entry_point': 'Phishing Emails with OneDrive '
'Sharing Links',
'high_value_targets': ['Government',
'Research',
'Policy-related Sectors']},
'investigation_status': 'Ongoing',
'lessons_learned': "The campaign highlights Kimsuky's adaptation of AI tools "
'and legitimate software to enhance espionage capabilities '
'while evading traditional defenses.',
'motivation': 'Cyber Espionage',
'post_incident_analysis': {'root_causes': ['Phishing',
'Malicious Chrome Extension',
'Abuse of Legitimate Remote Access '
'Tools']},
'references': [{'source': 'Enki'}],
'response': {'third_party_assistance': 'Enki (Researchers)'},
'threat_actor': 'Kimsuky',
'title': 'Kimsuky’s Latest Espionage Campaign Targets Gmail via Malicious '
'Chrome Extension',
'type': 'Espionage'}