Google: Kimsuky Uses AI-Generated Chrome Extension to Automatically Steal Gmail Data

Google: Kimsuky Uses AI-Generated Chrome Extension to Automatically Steal Gmail Data

Kimsuky’s Latest Espionage Campaign Targets Gmail via Malicious Chrome Extension

A new cyber espionage campaign attributed to the North Korean threat group Kimsuky has been uncovered, leveraging a malicious Chrome extension to steal Gmail data from victims in South Korea and Japan during the first half of 2026. The operation, identified by researchers at Enki, combines phishing, browser-based theft, and remote access tools to compromise targets.

Attack Chain & Tactics

The campaign begins with phishing emails containing OneDrive sharing links that deliver a Windows shortcut (LNK) file. When opened, the shortcut displays a decoy document while executing hidden commands to download additional malware, establishing a foothold on the victim’s system.

Key components of the attack include:

  • Malicious Chrome Extension: Named "Gmail automatic server uploader" (in Korean), the extension monitors Gmail activity, capturing emails, attachments, sender/recipient details, and message content without user awareness. Data is exfiltrated to an attacker-controlled server via encoded transmissions.
  • AI-Generated Code: The extension’s JavaScript files contain Korean comments, debugging text, and emojis, suggesting generative AI was used in its development.
  • Remote Access Tools: Kimsuky deployed Chrome Remote Desktop (with a UAC bypass for elevated privileges) and AnyDesk (hidden from view) to maintain persistence and full system control.
  • Email & Keylogging Theft: Beyond Gmail, the attackers harvested Thunderbird and Outlook emails, logged keystrokes, and conducted system reconnaissance to evade detection.

Evasion & Persistence Techniques

  • Rapidly Rotating C2 Servers: Kimsuky abused compromised Korean servers and free Japanese hosting services to obscure infrastructure.
  • Scheduled Tasks: A task named Chrome_Update ran every 15 minutes, allowing attackers to update malware post-infection.
  • Legitimate Software Abuse: The use of trusted remote-access tools (Chrome Remote Desktop, AnyDesk) complicates detection, as these are often whitelisted in enterprise environments.

Targets & Impact

The campaign focused on South Korean and Japanese individuals, likely in government, research, or policy-related sectors, given the decoy documents’ themes (e.g., "What Did Xi Jinping Do in Pyongyang?"). The multi-stage theft combining browser extensions, email clients, and keyloggers amplifies the risk of credential compromise, intellectual property theft, and long-term surveillance.

Indicators of Compromise (IoCs)

Enki’s report includes file hashes, IP addresses, URLs, and mutexes associated with the campaign. Key IoCs include:

  • Malicious LNK files (e.g., "習氏は何をしに平壌に行ったのか.lnk")
  • C2 Infrastructure: 103.77.242[.]187, 160.187.147[.]119
  • Exfiltration Endpoints: hxxps://sweet-iki-4263.holy[.]jp/gmail.php
  • Scheduled Tasks: Chrome_Update, User_Feed_Synchronization-{...}

The operation underscores Kimsuky’s adaptation of AI tools and legitimate software to enhance espionage capabilities while evading traditional defenses.

Source: https://cybersecuritynews.com/kimsuky-ai-generated-chrome-extension/

Google cybersecurity rating report: https://www.rankiteo.com/company/google

"id": "GOO1787581656",
"linkid": "google",
"type": "Cyber Attack",
"date": "1/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': ['Government',
                                     'Research',
                                     'Policy-related Sectors'],
                        'location': ['South Korea', 'Japan'],
                        'type': 'Individuals'}],
 'attack_vector': ['Phishing',
                   'Malicious Browser Extension',
                   'Remote Access Tools'],
 'data_breach': {'data_exfiltration': True,
                 'personally_identifiable_information': True,
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Emails',
                                              'Attachments',
                                              'Sender/Recipient Details',
                                              'Message Content',
                                              'Keystrokes']},
 'date_detected': '2026-01-01',
 'description': 'A new cyber espionage campaign attributed to the North Korean '
                'threat group Kimsuky has been uncovered, leveraging a '
                'malicious Chrome extension to steal Gmail data from victims '
                'in South Korea and Japan during the first half of 2026. The '
                'operation combines phishing, browser-based theft, and remote '
                'access tools to compromise targets.',
 'impact': {'data_compromised': ['Emails',
                                 'Attachments',
                                 'Sender/Recipient Details',
                                 'Message Content',
                                 'Keystrokes',
                                 'System Reconnaissance Data'],
            'identity_theft_risk': 'High',
            'operational_impact': 'Long-term surveillance and intellectual '
                                  'property theft',
            'systems_affected': ['Gmail',
                                 'Thunderbird',
                                 'Outlook',
                                 'Windows Systems']},
 'initial_access_broker': {'backdoors_established': ['Chrome Remote Desktop',
                                                     'AnyDesk'],
                           'entry_point': 'Phishing Emails with OneDrive '
                                          'Sharing Links',
                           'high_value_targets': ['Government',
                                                  'Research',
                                                  'Policy-related Sectors']},
 'investigation_status': 'Ongoing',
 'lessons_learned': "The campaign highlights Kimsuky's adaptation of AI tools "
                    'and legitimate software to enhance espionage capabilities '
                    'while evading traditional defenses.',
 'motivation': 'Cyber Espionage',
 'post_incident_analysis': {'root_causes': ['Phishing',
                                            'Malicious Chrome Extension',
                                            'Abuse of Legitimate Remote Access '
                                            'Tools']},
 'references': [{'source': 'Enki'}],
 'response': {'third_party_assistance': 'Enki (Researchers)'},
 'threat_actor': 'Kimsuky',
 'title': 'Kimsuky’s Latest Espionage Campaign Targets Gmail via Malicious '
          'Chrome Extension',
 'type': 'Espionage'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.