김수키(Kimsuky) 만든 구글 크롬 부가기능을 통한 악성코드(2023.3.20)

2023-05-16 Sakai Malicious code through Google Chrome add-on created by Kimsuky (2023.3.20)

https://wezard4u.tistory.com/6444

Thumbnail for 김수키(Kimsuky) 만든 구글 크롬 부가기능을 통한 악성코드(2023.3.20)

The Wezard4u analysis describes a Kimsuky-linked malicious Google Chrome extension used to steal email content from Gmail and potentially other Chromium-based browsers. The extension masquerades as “AF” or “Advanced Font,” requests broad permissions for tabs, navigation, cookies, and HTTP/HTTPS sites, and loads a background script that repeatedly contacts gonamod[.]com/sanghyon/index.php. The script can receive and execute remote JavaScript with eval, monitor browser events, handle messages, and includes helper routines for email validation, parameter extraction, and encoding. The report frames the activity as part of Kimsuky’s broader targeting of diplomats, journalists, government personnel, professors, politicians, and North Korea-related organizations.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 5f5432a5f992d8564c4db9074aaca1a… 2023-05-16 2023-05-16
HASH 11b99f460bf14c902083d2c9559da6f… 2023-05-16 2023-05-16
HASH 15d9903e7d475d6927e0687ca238642… 2023-05-16 2023-05-16
HASH a4daa30a2ef6943d8eec7759246f658… 2023-05-16 2023-05-16
URL https://gonamod.com/sanghyon/in… 2023-05-16 2023-05-16
HASH 012d5ffe697e33d81b9e7447f4aa338b 2023-03-20 2023-05-16
HASH 582a033da897c967faade386ac30f604 2023-03-20 2023-05-16
DOMAIN gonamod.com 2022-08-24 2023-05-16

Related Actors

Related Reports

« Back