Kimsuky Uses AI-Generated Chrome Extension to Automatically Steal Gmail Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Kimsuky has been linked to a new espionage campaign that turns a Chrome extension into a quiet Gmail collector.

The operation begins with convincing phishing emails and ends with attackers gaining access to messages, attachments, and a victim’s computer. Its mix of browser theft and remote control makes a single opened file especially risky.

The campaign targeted people in South Korea and Japan during the first half of 2026. Victims received a OneDrive sharing link leading to an archive containing a Windows shortcut file, or LNK.

Opening the shortcut displayed a decoy document while a hidden command downloaded more malware and established a foothold. Analysts at Enki identified the activity and linked it to Kimsuky through its tools, targeting, and operating patterns.

Enki said in a report shared with Cyber Security News (CSN) that the group rotated command servers quickly and also abused compromised Korean servers, making the campaign harder to trace.

Attack Overview (Source - Enki)
Attack Overview (Source – Enki)

The case shows why email compromise can start far beyond the inbox. The attackers collected local Thunderbird and Outlook mail, logged keystrokes, and installed legitimate remote-access software.

Earlier Kimsuky Chrome extension campaign reporting illustrates how browser add-ons have remained a useful channel for the group’s surveillance operations.

Kimsuky Uses AI-Generated Chrome Extension

The malicious extension, named “Gmail automatic server uploader” in Korean, was built to monitor Gmail pages. Its content script watched both the message-reading panel and the Send button.

When a user read or sent a message, it collected the sender or recipient, subject, message body, and any attachments. Attachments were fetched from their links, converted into an encoded form, and passed to a background script.

Japanese phishing email (Source - Enki)
Japanese phishing email (Source – Enki)

That script sent the stolen material to an attacker-controlled server, separating message content from files with a type setting. The design means data can leave the browser during normal email use, without a visible warning.

Researchers found detailed Korean comments, debugging text, and emoji embedded throughout the extension’s JavaScript and JSON files.

Those traits strongly suggest generative AI helped create much of the code. The finding echoes concerns raised in coverage of malicious AI browser extensions, where add-ons presented as useful tools instead became surveillance mechanisms.

The extension requested access across all URLs rather than limiting itself to Gmail. That wide reach would give the code room to run on other pages, although Enki’s analysis specifically documented Gmail theft.

The campaign’s operators used a free Japanese hosting service as the extension’s command-and-control destination.

Phishing Opens Wider Access

After the shortcut file ran, its Visual Basic script contacted a command server using the infected device’s MAC address and executed a returned PowerShell script in memory.

The first script created a scheduled task called Chrome_Update, configured to run every 15 minutes. This gave the operators a simple way to update their actions after the initial breach.

The follow-on scripts surveyed installed security tools and system details, then sent the results outward. Separate scripts copied messages from Thunderbird and Outlook mailboxes.

Joint South Korea and Germany cyber security advisory (Source - Enki)
Joint South Korea and Germany cyber security advisory (Source – Enki)

A keylogger captured typed input, including possible passwords, into a local log. Such overlapping collection methods can make mailbox theft more damaging than a browser-only incident.

Kimsuky also installed Chrome Remote Desktop and AnyDesk, legitimate programs that can provide full remote control when misused.

The Chrome Remote Desktop setup used a Windows UAC bypass technique to run with elevated privileges, while the AnyDesk workflow hid its window and icon.

Comparable AnyDesk phishing persistence tactics show why trusted remote tools deserve the same review as unfamiliar software.

Organizations should treat unexpected OneDrive share links and downloaded shortcut files as high risk, particularly when the file icon carries the small shortcut arrow.

Enki recommends checking such files before opening them and regularly reviewing scheduled tasks, installed remote-control tools, running processes, and browser extensions. Users should remove unknown extensions and report suspicious email links instead of opening them.

Security teams can hunt for the listed indicators, block known infrastructure, and check hosts for the named task and files before attackers return.

Indicators of compromise (IoCs):-

Type Indicator Description
MD5 8de25f181d32417fc34b2a77d2f4804b Phishing email sample
MD5 95d049f184c02aa756b361c2dacb354d 習氏は何をしに平壌に行ったのか.zip
MD5 cac69a696fc155717dabe641f22db0c9 習氏は何をしに平壌に行ったのか.lnk
MD5 18e33961d2007c89311f7754313292b3 pattern.zip
MD5 e7da02737751f2f171aed28694b9554e 5月9日資料.pdf.lnk
MD5 300f7b8ff182c8c69a0c499cdda6f8b8 米国のホルムズ逆封鎖は中国に効いている.zip
MD5 a2191f29f58b9f0cb576b7459ed6680d 米国のホルムズ逆封鎖は中国に効いている.lnk
MD5 94ed14ef07ac7504a3983ace8d894aae SDD_2026.zip
MD5 5b49177d14f073bd7abf4c94688ebd84 Directions and Parking information.lnk
MD5 4c5474238c4b2ec2ca0698902c084624 Invitation to SDD 2026 Breifing Session.lnk
MD5 7c6ac06ccfa7648a4a8cc916c14d9f67 JINF.pdf decoy document
MD5 77a7dfdc7bd74cc47ac3f4f8e019936c logo.png payload downloader
MD5 d7dbce5d25aa483d9c5ec1223ed6bf6e Thunderbird email-collection PowerShell script
MD5 e8aaa4f579e6be788929d3548b31bf6d Outlook email-collection PowerShell script
MD5 5727c0ff18c58b80bca5ce80575996bd Chrome Remote Desktop installation PowerShell script
MD5 633e672cce390d75f44f2e2357dec7b31 .bat file used in Chrome Remote Desktop installation
MD5 0210f46648d4e36a98c2c0fae404f36d background.js
MD5 3ad9fbfad7ffb569b1aa24d4588edc60 content.js
MD5 f6f7a94c11ea0ee01cbbe674cfac7851 manifest.json
MD5 54089d9cf9c7d5ff9abbae88437f66a8 AnyDesk installation batch file
MD5 51e1876c971c76d9664ad198af8a5b61 app.vmd
MD5 c08ea73bac08ea4f4665e9e0b0fdd2a8 mnfst.vmd
MD5 eb80f7bddb699784baa9fbf2941eaf4a attach.vmd
MD5 c774b3980151881d9d546710126b5ded sch.vmd
MD5 f3620e42e9c726c65ea7e14e3bf35464 vpost.vmd
MD5 8e4410c65ca11664561e1b6036209122 bimage.vmd
IP address 103.77.242[.]187 Command-and-control infrastructure
IP address 160.187.147[.]119 AnyDesk-related payload delivery server
IP address 84.247.145[.]65 Infrastructure indicator listed by Enki
IP address 210.183.177[.]217 Compromised Korean server used as command-and-control infrastructure
IP address 103.249.117[.]183 Chrome Remote Desktop command-and-control infrastructure
URL hxxps://1drv[.]ms/u/c/2c732f3239360d98/IQDihidlH5aGTK-prrMLTrBIAcbEYFb4_w7HUbeFeiZU6Go?e=wpzaBO Malicious OneDrive share link
URL hxxp://103.77.242[.]187/JINF.pdf Decoy document URL
URL hxxp://103.77.242[.]187/logo.png Download location for the VBE payload
URL hxxp://103.77.242[.]187/view.php?type=apple&seed=<MAC Address> Initial command-and-control request
URL hxxp://103.249.117[.]183/1.bat Chrome Remote Desktop installation script
URL hxxp://103.249.117[.]183/receive.php Data-exfiltration endpoint
URL hxxps://sweet-iki-4263.holy[.]jp/gmail.php Gmail data-exfiltration endpoint
URL hxxp://160.187.147[.]119/any/app.vmd AnyDesk component download
URL hxxp://160.187.147[.]119/any/mnfst.vmd AnyDesk component download
URL hxxp://160.187.147[.]119/any/attach.vmd AnyDesk component download
URL hxxp://160.187.147[.]119/any/sch.vmd AnyDesk component download
URL hxxp://160.187.147[.]119/any/vpost.vmd AnyDesk component download
URL hxxp://160.187.147[.]119/any/bimage.vmd AnyDesk task-definition download
Mutex MyAnyMutexName Used to prevent duplicate AnyDesk-related script execution
Scheduled task Chrome_Update Runs bot.vbe every 15 minutes for persistence
Scheduled task User_Feed_Synchronization-{0DDC1BD9-E733-425C-B92B-ABAC149AB11232} Executes the hidden AnyDesk workflow every five minutes

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

The post Kimsuky Uses AI-Generated Chrome Extension to Automatically Steal Gmail Data appeared first on Cyber Security News.