TRANSLATEXT Malware

General News

Summary

The North Korean threat group Kimsuky has been associated with a new threatening Google Chrome extension aimed at harvesting sensitive information for intelligence gathering. Kimsuky, a well-known hacking group from North Korea active since at least 2012, engages in cyber espionage and financially motivated attacks against South Korean targets. Associated with the Lazarus cluster and part of the Reconnaissance General Bureau (RGB), Kimsuky is also identified by names such as APT43, ARCHIPELAGO, Black Banshee, Emerald Sleet, Springtail, and Velvet Chollima. This backdoor, which appears to be previously undocumented, enables attackers to conduct basic reconnaissance and deploy additional payloads for taking over or remotely controlling the machine. Researchers note that discovered evidence on GitHub suggest that Kimsuky intended to minimize exposure and use the malware for a short period to target specific individuals.

Classifications

industries
Entertainment
applications
Customer Service & Support

AskAI Classifications

Labels
Cybersecurity Software Anti-Malware Software SaaS Security

Linked Companies

EnigmaSoft
$1M to $5M