Kimsuky Using TRANSLATEXT Chrome Extension to Steal Sensitive Data
As part of a continuing intelligence gathering operation, the use of a new malicious Google Chrome extension that is intended to steal sensitive information has been connected to the North Korea-affiliated threat actor known as Kimsuky.
After noticing the activity in early March 2024, Zscaler ThreatLabz nicknamed the extension TRANSLATEXT, emphasizing its capacity to collect cookies, browser screenshots, email addresses, usernames, and passwords.
It is claimed that the targeted effort was launched against academics in South Korea who specialize in North Korean political issues.
Kimsuky is a well-known North Korean hacker group that has been operating since at least 2012. They plan financially driven attacks and cyberespionage against South Korean organizations read more about Kim...

