North Korean state-sponsored hackers deployed an AI-generated Chrome extension that silently steals Gmail data from targets, marking a new front in Pyongyang’s cyber espionage arsenal.
Security researchers at Enki identified the campaign targeting South Korean officials and policy experts with a malicious browser add-on designed to monitor and extract email content in real time. The extension, named “Gmail automatic server uploader” in Korean, watches both the message-reading panel and the Send button, forwarding stolen material to attacker-controlled servers without any visible warning to the user.
How the Extension Works
The malicious extension requests access across all URLs rather than limiting itself to Gmail, giving it broad reach to execute code on multiple pages. Its content script monitors incoming and outgoing messages, separating email body text from file attachments and transmitting both to infrastructure hosted in South Korea, making the campaign harder to trace back to Pyongyang.
The attack begins with spear-phishing emails using politically themed lures about North Korean diplomacy, including files referencing Chinese President Xi Jinping’s visits to Pyongyang. Once a target opens the attached document, the payload installs the Chrome extension along with remote access tools including Chrome Remote Desktop and AnyDesk for persistent control.
Persistence and Evasion Tactics
To maintain access, the attackers used a Windows User Account Control bypass to install Chrome Remote Desktop with elevated privileges. AnyDesk was configured to hide its window and system tray icon, making the remote access invisible to the victim. This combination of browser-based data theft and remote desktop access gives Kimsuky persistent surveillance capabilities.
The campaign echoes earlier Kimsuky operations that used malicious browser extensions for surveillance, but the use of AI to generate the extension code represents an evolution in sophistication. By automating part of the development process, the group can produce tailored tools faster and scale its targeting across more victims.
Researchers linked the infrastructure to previous Kimsuky campaigns, including the TranslateX extension scheme documented earlier this year. The phishing servers were registered through services designed to obscure ownership, consistent with known North Korean operational patterns.
The findings come amid a broader surge in state-sponsored cyber activity. A threat intelligence report by S2W found that state-backed hacking from North Korea, China, and Russia rose 7.5 percent in the first half of 2026, with North Korea accounting for 99 of the recorded Advanced Persistent Threat incidents globally.
discussion