TRANSLATEXT is a malicious Google Chrome extension attributed in the provided content to the North Korea-linked Kimsuky threat actor. It was reported by Zscaler in 2024 and was masqueraded as a legitimate extension using the filename GoogleTranslate.crx. The extension can inject arbitrary JavaScript into specific pages; when a victim visits nid.naver.com, the Naver login page, it injects auth.js to steal login credentials. The content states that TRANSLATEXT contains four JavaScript files used for bypassing defenses, collecting sensitive information and screenshots, and exfiltrating data. It is described as capable of form-grabbing and event-listening to extract data from web forms, stealing credentials stored in Chrome, and stealing and exfiltrating updated cookies from Google, Naver, Kakao, and Daum to command-and-control infrastructure. For C2, the malware has used a GitHub repository and a dead drop resolver on a public blog site to retrieve configuration and commands, and it exfiltrates collected credentials and cookies to its C2 server. Persistence/installation-related behavior in the content includes querying and modifying HKCU\Software\Policies\Google\Chrome\ExtensionInstallForcelist to check for installed Chrome extensions and to grant permission to install specified extensions. High-confidence indicators and artifacts directly mentioned in the content include the filename GoogleTranslate.crx, the injected script auth.js, the targeted site nid.naver.com, use of GitHub and a public blog as C2/dead-drop infrastructure, and the registry key HKCU\Software\Policies\Google\Chrome\ExtensionInstallForcelist.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In 2024, Zscaler discovered a new Google Chrome extension called TRANSLATEXT developed by Kimsuky. This extension can inject arbitrary JS scripts when visiting specific pages. Upon visiting nid.naver.com - the Naver login page - the extension injects auth.js into the browser to steal the login credentials.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
Agent Tesla has the ability to use form-grabbing to extract data from web data forms. Kimsuky has the ability to use form-grabbing to extract emails and passwords from web data forms. TRANSLATEXT has the ability to use form-grabbing and event-listening to extract data from web data forms. XLoader can conduct form grabbing, steal cookies, and extract data from HTTP sessions.
"APT42 has used custom malware to steal login and cookie data from common browsers." / "...extracts the web session cookie and sends it to the C2 server." / "...stole Chrome browser cookies by copying the Chrome profile directories of targeted users."
"Agent Tesla can gather credentials from a number of browsers." / "...custom-developed malware, which collected passwords from the Firefox browser storage." / "...used BrowserGhost, a tool designed to obtain credentials from browsers..." / "...stole users' saved passwords from Chrome."
Agent Tesla has the ability to use form-grabbing to extract data from web data forms. Kimsuky has the ability to use form-grabbing to extract emails and passwords from web data forms. TRANSLATEXT has the ability to use form-grabbing and event-listening to extract data from web data forms. XLoader can conduct form grabbing, steal cookies, and extract data from HTTP sessions.
The content repeatedly describes threat actors, malware, and campaigns using HTTP and/or HTTPS for command and control, including examples such as BlackEnergy communicating with C2 over HTTP POST requests and many other families using HTTP/S for C2.
The adversaries had communicated to both Dropbox and Pastebin. APT28 has used Google Drive for C2. APT37 leverages social networking sites and cloud platforms (AOL, Twitter, Yandex, Mediafire, pCloud, Dropbox, and Box) for C2.
...TRANSLATEXT and a dead drop resolver to retrieve configurations and commands from a public blog site.
"APT39 has communicated with C2 through files uploaded to and downloaded from DropBox."; "RIFLESPINE can retrieve C2 commands from an encrypted file on Google Drive then upload the results ... back to Google Drive."; "CloudDuke uses a Microsoft OneDrive account to exchange commands and stolen data"
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malicious Chrome extension that injects JavaScript into targeted pages, including Naver login, to steal credentials.
A malicious Chrome extension that injects JavaScript into targeted pages, including Naver login pages, to steal credentials.
Backdoor that uses a GitHub repository as a command-and-control channel.
Malware that uses a GitHub repository for command and control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.