Sharp Tongue
2022-07-28 • Volexity • SharpTongue Deploys Clever Mail-Stealing Browser …
Volexity uses SharpTongue to track a North Korean threat actor whose activity is often lumped by other researchers under the broader Kimsuky label, though Volexity treats it as a distinct, well-documented cluster. SharpTongue primarily targets individuals and organizations in the United States, Europe, and South Korea working on North Korea policy, nuclear issues, and weapons systems, including journalists, government officials, academics, and think tanks, aiming to steal credentials and maintain persistent access to email and files. Its hallmark technique is patient social engineering: attackers build rapport through extended, non-malicious email exchanges, sometimes soliciting written papers or proposing fake in-person meetings, before delivering password-protected, macro-laden documents (often loading BabyShark VBScript malware) or credential-harvesting links. Since September 2021, Volexity has also observed SharpTongue deploying a malicious Chrome, Edge, or Whale browser extension it calls SHARPEXT, which, once a system is already compromised, directly inspects and exfiltrates Gmail and AOL webmail content from within the victim's logged-in browser session using a hidden DevTools-based mechanism, evading typical email-provider security alerts.
-
43
Related Actors
-
799
Related Reports
Related Actors
Related Reports in This Cluster
Top Authors
View Sharp Tongue reports only