Mastodon Skip to content
pulseofnations. Real News. Global Impact.
live markets
S&P 5007,652.86▲ 3.25%NASDAQ25,980.19▲ 4.02%DOW53,417.16▲ 2.83%GOLD4,698.90▲ 15.52%WTI84.50▼ 5.39%BRENT91.58▼ 5.37%EUR/USD1.1656▲ 2.45%USD/JPY159.32▼ 2.75%DXY99.08▼ 2.35%BTC$80,710▲ 4.69%ETH$2,508▲ 2.54%SOL$101.75▲ 8.28%TOTAL CRYPTO$2.73T▲ 1.74%

North Korea Deploys AI-Built Chrome Extension to Steal Gmail

Kimsuky hackers used an AI-generated Chrome extension that automatically exfiltrates Gmail messages and attachments to North Korean servers

Partner Surfshark VPN

North Korean state-sponsored hackers deployed an AI-generated Chrome extension that silently steals Gmail data from targets, marking a new front in Pyongyang’s cyber espionage arsenal.

Security researchers at Enki identified the campaign targeting South Korean officials and policy experts with a malicious browser add-on designed to monitor and extract email content in real time. The extension, named “Gmail automatic server uploader” in Korean, watches both the message-reading panel and the Send button, forwarding stolen material to attacker-controlled servers without any visible warning to the user.

How the Extension Works

The malicious extension requests access across all URLs rather than limiting itself to Gmail, giving it broad reach to execute code on multiple pages. Its content script monitors incoming and outgoing messages, separating email body text from file attachments and transmitting both to infrastructure hosted in South Korea, making the campaign harder to trace back to Pyongyang.

The attack begins with spear-phishing emails using politically themed lures about North Korean diplomacy, including files referencing Chinese President Xi Jinping’s visits to Pyongyang. Once a target opens the attached document, the payload installs the Chrome extension along with remote access tools including Chrome Remote Desktop and AnyDesk for persistent control.

Persistence and Evasion Tactics

To maintain access, the attackers used a Windows User Account Control bypass to install Chrome Remote Desktop with elevated privileges. AnyDesk was configured to hide its window and system tray icon, making the remote access invisible to the victim. This combination of browser-based data theft and remote desktop access gives Kimsuky persistent surveillance capabilities.

The campaign echoes earlier Kimsuky operations that used malicious browser extensions for surveillance, but the use of AI to generate the extension code represents an evolution in sophistication. By automating part of the development process, the group can produce tailored tools faster and scale its targeting across more victims.

Researchers linked the infrastructure to previous Kimsuky campaigns, including the TranslateX extension scheme documented earlier this year. The phishing servers were registered through services designed to obscure ownership, consistent with known North Korean operational patterns.

The findings come amid a broader surge in state-sponsored cyber activity. A threat intelligence report by S2W found that state-backed hacking from North Korea, China, and Russia rose 7.5 percent in the first half of 2026, with North Korea accounting for 99 of the recorded Advanced Persistent Threat incidents globally.

SourcesCyber Security News; S2W Threat Intelligence Report (August 2026); Korea Times
React to this dispatch
Share this dispatch X WhatsApp Bluesky Report an error
Written by

Founder and editor of Pulse of Nations, an independent wire service covering war, geopolitics, markets and technology.

discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Next dispatch CoinbaseCartel Blitz Hits 13+ Firms Across 7 Countries Read →