Thursday, October 3, 2024
Homecyber securityNorth Korean Hackers Attack Gmail Users With Malicious Chrome Extensions

North Korean Hackers Attack Gmail Users With Malicious Chrome Extensions

Published on

In a collaborative effort, the German Federal Office for the Protection of the Constitution (BfV) and the National Intelligence Service of the Republic of Korea (NIS) has released a significant cybersecurity advisory.

This advisory cautions against the stealthy actions of a hacking group known as Kimsuki “Kim Su-ki” (aka Thallium, Velvet Chollima) that was found using malicious Chrome extensions to steal sensitive information from the targets’ Gmail accounts by gaining unauthorized access.

North Korean threat group Kimsuky conducts cyber espionage against the following entities by means of spear phishing:-

- Advertisement - EHA
  • Diplomats
  • Journalists
  • Government agencies
  • University professors
  • Politicians

The initial focus of the threat actors was on targets located within South Korea. However, over time, they have significantly broadened their operations to include the entities in the following regions:-

  • The United States
  • Europe

Moreover, to perform and execute the attack on targets, the threat actors have used two methods:-

  • A malicious Chrome extension
  • Android applications

As we hinted earlier, the current Kimsuky campaign mainly targets individuals located in South Korea only.

However, the same TTPs could be used by threat actors to target victims globally. So, it’s completely important to stay alert of the TTPs used by the threat actors and mitigate such scenarios by detecting them.

Attack Strategy

The Kimsuky attack strategy commences with a targeted spear-phishing email that urges the victim to install a malicious Chrome extension.

It is important to note that apart from Chrome browser, this extension can also infect other Chromium-based browsers like:-

  • Microsoft Edge
  • Brave

The extension can be identified as “AF” and may not appear on the extensions list under normal circumstances. To identify the malicious extension utilized in the Kimsuky attack, users must enter the following address in the address bar of the browser:-

  • (chrome|edge|brave)://extensions

The extension automatically activates the victim’s browser once they visit Gmail via the infected browser. It intercepts and steals the contents of the victim’s email account as soon as they click on it.

The extension employs a technique that leverages the Devtools API available in the browser to send stolen data to the server under the attacker’s control.

For this attack, Kimsuky used the following hashes for its malicious files:-

  • 012d5ffe697e33d81b9e7447f4aa338b
  • 51527624e7921a8157f820eb0ca78e29
  • 582a033da897c967faade386ac30f604
  • 04bb7e1a0b4f830ed7d1377a394bc717
  • 89f97e1d68e274b03bc40f6e06e2ba9a
  • 3458daa0dffdc3fbb5c931f25d7a1ec0

Kimsuki uses the following Android malware to infect Android devices:-

  • FastViewer
  • Fastfire
  • Fastspy DEX

Since the hashes of FastViewer were already revealed publicly by the researchers, so, in December 2022, the threat actors updated FastViewer to make continued use of it.

A phishing email or other attack led Kimsuki operators to steal the victim’s Google account, which it used to log into the account. It has also become evident that the hackers abuse Google Play’s feature that synchronizes information from the web to the phone.

The feature enables users to install applications on their linked devices directly from their computers, providing an avenue for installing malware onto these devices.

The attackers submit the malicious app to the Google Play console developer site under the guise of “internal testing only.” They then add the victim’s device as a testing target, requesting Google Play to install the malicious app onto the victim’s device.

The Android malware utilized by Kimsuky is a RAT that provides attackers with a range of capabilities to carry out their malicious activities like:-

  • Drop malicious payload
  • Create files
  • Delete files
  • Steal files
  • Get contact lists
  • Perform calls
  • Monitor SMS
  • Send SMS
  • Activate the camera
  • Perform keylogging
  • View the desktop

With the ever-evolving tactics of Kimsuky in compromising Gmail accounts, it is imperative that both individuals and organizations remain proactive in implementing comprehensive security measures.

Building Your Malware Defense Strategy – Download Free E-Book

Related Read:

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Northern Ireland Police to Pay £750,000 Fine Following Data Breach

The Police Service of Northern Ireland (PSNI) has been ordered to pay a £750,000...

ANY.RUN Upgrades Threat Intelligence to Identify Emerging Threats

ANY.RUN announced an upgrade to its Threat Intelligence Portal, enhancing its capabilities to identify...

Cisco Nexus Vulnerability Let Hackers Execute Arbitrary Commands on Vulnerable Systems

A critical vulnerability has been discovered in Cisco's Nexus Dashboard Fabric Controller (NDFC), potentially...

Hackers Now Exploit Ivanti Endpoint Manager Vulnerability to Launch Cyber Attacks

The Cybersecurity and Infrastructure Security Agency (CISA) has announced the addition of a new...

Free Webinar

Decoding Compliance | What CISOs Need to Know

Non-compliance can result in substantial financial penalties, with average fines reaching up to $4.5 million for GDPR breaches alone.

Join us for an insightful panel discussion with Chandan Pani, CISO - LTIMindtree and Ashish Tandon, Founder & CEO – Indusface, as we explore the multifaceted role of compliance in securing modern enterprises.

Discussion points

The Role of Compliance
The Alphabet Soup of Compliance
Compliance
SaaS and Compliance
Indusface's Approach to Compliance

More like this

Northern Ireland Police to Pay £750,000 Fine Following Data Breach

The Police Service of Northern Ireland (PSNI) has been ordered to pay a £750,000...

Cisco Nexus Vulnerability Let Hackers Execute Arbitrary Commands on Vulnerable Systems

A critical vulnerability has been discovered in Cisco's Nexus Dashboard Fabric Controller (NDFC), potentially...

Hackers Now Exploit Ivanti Endpoint Manager Vulnerability to Launch Cyber Attacks

The Cybersecurity and Infrastructure Security Agency (CISA) has announced the addition of a new...