News North Korean hackers use Google Chrome extension to steal researchers’ emailsExtension uploaded to GitHub impersonates Google Translate to steal data, using new methods to bypass email security A North Korean cybercrime group known for its espionage campaigns deployed a new extension for the Google Chrome web browser to steal data from South Korean targets, according to a U.S. cloud security firm. ZScaler ThreatLabz said in a report published on Thursday that it observed the state-backed threat actor Kimsuky using an extension that impersonates Google Translate and steals users’ email addresses, usernames, passwords and browser cookies, in addition to capturing browser screenshots. The new extension, dubbed “TRANSLATEXT” by ZScaler, was seemingly aimed at South Korean academics, particularly those involved in DPRK-focused political © Korea Risk Group. All rights reserved. |