Volexity reported that the threat actor SharpTongue deployed a malicious browser extension dubbed SHARPEXT to steal email from victims using webmail through their browsers. The malware was designed to work inside the browser session rather than against the mail provider directly, allowing the attackers to capture mailbox contents and likely bypass protections that focus on account compromise or server-side abuse.
The operation highlighted a targeted espionage technique in which a browser extension provided persistent access to victim communications after installation. By abusing the trust and access granted to browser add-ons, SHARPEXT enabled covert collection of sensitive email data from active user sessions, underscoring the security risk posed by malicious extensions in enterprise environments.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
Volexity published research describing SHARPEXT, a browser extension used by the threat actor SharpTongue to steal email data. The disclosure publicly revealed technical details of the malware and its use in espionage activity.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.