김수키(Kimsuky) 만든 구글 크롬 부가기능을 통한 악성코드(2023.3.20)
2023-05-16 • Sakai • Malicious code through Google Chrome add-on created by Kimsuky (2023.3.20) •
The Wezard4u analysis describes a Kimsuky-linked malicious Google Chrome extension used to steal email content from Gmail and potentially other Chromium-based browsers. The extension masquerades as “AF” or “Advanced Font,” requests broad permissions for tabs, navigation, cookies, and HTTP/HTTPS sites, and loads a background script that repeatedly contacts gonamod[.]com/sanghyon/index.php. The script can receive and execute remote JavaScript with eval, monitor browser events, handle messages, and includes helper routines for email validation, parameter extraction, and encoding. The report frames the activity as part of Kimsuky’s broader targeting of diplomats, journalists, government personnel, professors, politicians, and North Korea-related organizations.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 5f5432a5f992d8564c4db9074aaca1a… | 2023-05-16 | 2023-05-16 |
| HASH | 11b99f460bf14c902083d2c9559da6f… | 2023-05-16 | 2023-05-16 |
| HASH | 15d9903e7d475d6927e0687ca238642… | 2023-05-16 | 2023-05-16 |
| HASH | a4daa30a2ef6943d8eec7759246f658… | 2023-05-16 | 2023-05-16 |
| URL | https://gonamod.com/sanghyon/in… | 2023-05-16 | 2023-05-16 |
| HASH | 012d5ffe697e33d81b9e7447f4aa338b | 2023-03-20 | 2023-05-16 |
| HASH | 582a033da897c967faade386ac30f604 | 2023-03-20 | 2023-05-16 |
| DOMAIN | gonamod.com | 2022-08-24 | 2023-05-16 |