김수키(Kimsuky) 만든 구글 크롬 부가기능을 통한 악성코드(2023.3.20)

2023-05-16 • Sakai • Malicious code through Google Chrome add-on created by Kimsuky (2023.3.20) •

https://wezard4u.tistory.com/6444

Thumbnail for 김수키(Kimsuky) 만든 구글 크롬 부가기능을 통한 악성코드(2023.3.20)

The Wezard4u analysis describes a Kimsuky-linked malicious Google Chrome extension used to steal email content from Gmail and potentially other Chromium-based browsers. The extension masquerades as “AF” or “Advanced Font,” requests broad permissions for tabs, navigation, cookies, and HTTP/HTTPS sites, and loads a background script that repeatedly contacts gonamod[.]com/sanghyon/index.php. The script can receive and execute remote JavaScript with eval, monitor browser events, handle messages, and includes helper routines for email validation, parameter extraction, and encoding. The report frames the activity as part of Kimsuky’s broader targeting of diplomats, journalists, government personnel, professors, politicians, and North Korea-related organizations.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://gonamod.com/sanghyon/in… 2023-05-16 2023-05-16
HASH 11b99f460bf14c902083d2c9559da6f… 2023-03-20 2023-05-16
HASH a4daa30a2ef6943d8eec7759246f658… 2023-03-20 2023-05-16
DOMAIN gonamod.com 2022-08-24 2023-05-16

Related Actors

Related Reports

« Back