GemStone is a malicious Chromium browser extension and browser-surveillance backdoor associated with TA412, also known as Violet Typhoon and APT31. It masquerades as a Google Gemini AI browsing companion and was deployed against U.S. nongovernmental organizations, mining companies, and commodity-trading organizations through spearphishing campaigns using internship- and academic-conference-themed lures. GemStone supports keylogging, theft of browser cookies and stored browser data, browsing-event collection, screenshot capture, command execution, and command-and-control-directed HTTP requests. It can transmit collected information to its operators, enabling credential theft and browser-session compromise. The reported activity delivered the extension through an installer following browser and Windows exploitation, targeting Chromium users on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The final stage leverages a Windows kernel local privilege escalation flaw, CVE-2026-85880, which uses Advanced Local Procedure Call and Windows Notification Facility mechanisms to gain kernel read/write access and elevate privileges within the browser process. | TA412 used spearphishing lures ... ultimately installing a malicious browser extension disguised as “Google Gemini” that Proofpoint tracks as GemStone.
The first is a type-confusion flaw in Chromium’s V8 JavaScript engine, tracked as CVE-2026-85046, which enables remote code execution inside the browser renderer by abusing an optimization bug in V8’s JIT compiler. | TA412 used spearphishing lures ... ultimately installing a malicious browser extension disguised as “Google Gemini” that Proofpoint tracks as GemStone.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The extension functions as a full browser-surveillance backdoor capable of keylogging, cookie theft, screenshot capture, and arbitrary HTTP requests via command-and-control infrastructure.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
TA412 used spearphishing lures posing as university interns and academic conference outreach... UNK_LateNight targeted US aerospace companies with defense-themed procurement lures... UNK_QuietRacket targeted government and financial organizations... using conference-themed phishing.
GemStone functions as a full browser-surveillance backdoor capable of keylogging, cookie theft, screenshot capture, and arbitrary HTTP requests.
23 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malicious browser extension masquerading as Google Gemini that provides browser surveillance, including keylogging, cookie theft, screenshot capture, and arbitrary HTTP requests through C2 infrastructure.
A malicious browser extension acting as a browser-surveillance backdoor. It can keylog, steal cookies, capture screenshots, and make arbitrary HTTP requests through command-and-control infrastructure.
A malicious Chromium browser extension installed following BlueMoon exploitation in TA412 activity. It captures keystrokes, cookies, browser storage, session data, browsing/navigation data, screenshots, and can execute operator commands including arbitrary HTTP requests and script injection through its extension context.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.