#SHARPEXT

Malware/Tool

2022-07-28 • SharpTongue Deploys Clever Mail-Stealing Browser Extension “SHARPEXT”

SHARPEXT is described as a mail-stealing browser extension deployed by SharpTongue, a threat actor believed to be North Korean and often publicly called Kimsuky. Separate Black Hat NOC observations recorded repeated DNS callouts from four hosts to three domains associated with SHARPEXT, including activity tied to a known C2 domain. The reports place the malware in an espionage-oriented North Korean context and note the actor’s interest in security researchers and security employees.

Tagged Reports

« Back