Kimsuky Uses AI-Generated Chrome Extension to Steal Gmail Data
Key Takeaways The Kimsuky threat group has deployed a new espionage campaign utilizing an AI-generated Chrome extension to covertly exfiltrate Gmail data. The attack chain begins with sophisticated...
Key Takeaways
- The Kimsuky threat group has deployed a new espionage campaign utilizing an AI-generated Chrome extension to covertly exfiltrate Gmail data.
- The attack chain begins with sophisticated phishing emails delivering malicious OneDrive links that lead to a Windows shortcut (.LNK) file.
- Victims in South Korea and Japan were targeted in the first half of 2026.
- Beyond Gmail theft, the campaign also installs keyloggers, steals data from Thunderbird and Outlook, and deploys legitimate remote access tools like Chrome Remote Desktop and AnyDesk for persistent control.
- The use of AI in generating the Chrome extension’s code highlights an evolving tactic by advanced persistent threat (APT) groups.
The Kimsuky advanced persistent threat (APT) group has launched a sophisticated new espionage campaign, leveraging a custom-built Chrome extension, likely generated with artificial intelligence, to discreetly steal sensitive Gmail data. This operation represents a significant escalation in the group’s tactics, combining browser-based data exfiltration with broader system compromise and remote control capabilities.
Table Of Content
The attack initiates with highly convincing phishing emails, designed to lure targets into clicking a malicious OneDrive sharing link. This link leads to an archive containing a Windows shortcut file (.LNK), which, once opened, triggers a multi-stage infection process, ultimately granting attackers extensive access to victims’ communications and systems.
Security researchers at Enki observed this campaign targeting individuals in South Korea and Japan during the first six months of 2026. Enki said in a report that their analysis linked the activity to Kimsuky based on the group’s characteristic tools, targeting methodologies, and operational patterns. The group further complicated attribution by rapidly rotating command servers and exploiting compromised Korean servers, making the campaign more challenging to trace.
AI-Generated Chrome Extension Facilitates Covert Gmail Theft
Central to this new campaign is a malicious Chrome extension, identified as “Gmail automatic server uploader” in Korean. Its primary function is to monitor Gmail activity and exfiltrate sensitive information without user detection. The extension’s content script actively observes both the Gmail message-reading panel and the “Send” button.
Upon a user reading or sending an email, the extension meticulously collects the sender or recipient details, subject line, message body, and any attachments. Attachments are retrieved via their embedded links, encoded, and then passed to a background script for exfiltration. This design allows for seamless data theft during routine email usage, without triggering any visible alerts to the victim.
Researchers investigating the extension’s code discovered extensive Korean comments, debugging messages, and even emojis embedded within its JavaScript and JSON files. These elements strongly suggest that generative AI tools were instrumental in the development of a significant portion of the code. This finding aligns with growing concerns about the potential misuse of AI in creating malicious browser extensions, which often masquerade as legitimate utilities while secretly performing surveillance.
Notably, the extension demanded broad permissions, requesting access across “all URLs” rather than restricting itself solely to Gmail. While Enki’s analysis focused on Gmail data exfiltration, this wide-ranging access provides the attackers with the flexibility to execute code and potentially steal data from other web pages, extending the scope of their surveillance capabilities. The command-and-control (C2) infrastructure for the extension utilized a free Japanese hosting service.
Phishing Tactics Lead to Extensive System Compromise
The initial phase of the attack chain is critical for establishing a foothold. When a victim opens the malicious shortcut file, a Visual Basic script embedded within it contacts a C2 server, transmitting the infected device’s MAC address. The server then responds by delivering a PowerShell script, which is executed directly in memory, minimizing its footprint on disk.
One of the first actions performed by this PowerShell script is the creation of a scheduled task named “Chrome_Update,” configured to run every 15 minutes. This persistent mechanism ensures that the attackers can maintain and update their malicious activities on the compromised system following the initial breach.
Subsequent scripts deployed by the attackers perform reconnaissance, gathering information about installed security tools and detailed system configurations. This intelligence is then sent back to the C2 server. Separate scripts are specifically designed to copy email messages from both Thunderbird and Outlook mailboxes, demonstrating a comprehensive approach to data collection beyond just Gmail.
A keylogger is also installed, discreetly capturing all typed input, including sensitive information such as passwords, and storing it in a local log file. These multifaceted data collection strategies make the incident far more damaging than a simple browser-only compromise, as attackers gain access to a wide array of personal and professional communications and credentials.
Further escalating the compromise, Kimsuky installs legitimate remote access software, specifically Chrome Remote Desktop and AnyDesk. These tools, while legitimate, are abused to gain full remote control over the compromised systems. The Chrome Remote Desktop installation leverages a Windows User Account Control (UAC) bypass technique to execute with elevated privileges, granting the attackers administrative control. The AnyDesk deployment is configured to hide its window and icon, ensuring it operates stealthily.
The use of trusted remote access tools for malicious purposes underscores the importance of scrutinizing all software, even seemingly benign applications. Organizations must treat unexpected prompts or installations of such tools with the same level of suspicion as unknown, overtly malicious software.
Enki advises organizations to exercise extreme caution with unexpected OneDrive sharing links and any downloaded shortcut files, especially those displaying the small shortcut arrow icon. Proactive measures include verifying such files before opening them, regularly reviewing scheduled tasks, auditing installed remote-control software, monitoring running processes, and inspecting browser extensions. Users should remove any unfamiliar extensions and report suspicious email links rather than interacting with them.
Security teams are encouraged to actively hunt for the provided indicators of compromise, block known malicious infrastructure, and perform forensic checks on hosts for the presence of the named scheduled tasks and files to preempt further attacker actions.
What You Should Do
- Be Vigilant Against Phishing: Exercise extreme caution with emails containing unexpected links, especially those leading to cloud storage services like OneDrive. Verify the sender and content independently before clicking.
- Inspect Downloaded Files: Before opening any downloaded archive or shortcut file, particularly those with the .LNK extension, inspect it thoroughly. Be wary of files with the small shortcut arrow icon that appear suspicious.
- Review Browser Extensions: Regularly audit your installed browser extensions. Remove any extensions you don’t recognize, no longer use, or that request overly broad permissions (e.g., “access your data on all websites”).
- Monitor System Processes and Scheduled Tasks: Implement monitoring for unusual processes and newly created scheduled tasks on endpoints. Investigate any unfamiliar entries, such as “Chrome_Update.”
- Restrict Remote Access Tools: Strictly control and monitor the installation and use of legitimate remote access tools like Chrome Remote Desktop and AnyDesk. Ensure they are only used by authorized personnel for legitimate purposes and are configured securely.
- Implement Email Security Solutions: Deploy advanced email security gateways that can detect and block sophisticated phishing attempts and malicious attachments.
- Educate Users: Conduct regular cybersecurity awareness training for all employees, emphasizing the dangers of phishing, suspicious links, and the importance of reporting unusual activity.
- Utilize Indicators of Compromise (IoCs): Security teams should integrate the provided IoCs (MD5 hashes, IP addresses, URLs, Mutexes, Scheduled tasks) into their threat intelligence platforms (e.g., MISP, VirusTotal, SIEM) to detect and block malicious activity.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.