Cybersecurity firm Volexity states that the malicious extension 'SharpTongue' is capable of stealing email content from Gmail and AOL
Representative Image
A group of hackers from North Korea is using a malicious Google Chrome or Chromium-based Microsoft Edge extension to spy or user email accounts, according to cybersecurity firm Volexity. The malicious extension by the hacker group titled 'SharpTongue' is capable of stealing email content from Gmail and AOL.
ADVERTISEMENT
SharpTongue is targeting and victimising individuals working for organisations in the United States, Europe and South Korea who work on topics involving North Korea, nuclear issues, weapons systems, and other matters of strategic interest to North Korea. Within the last year, Volexity has responded to multiple incidents involving SharpTongue and, in most cases, has discovered a malicious Google Chrome or Microsoft Edge extension dubbed as 'SHARPEXT'.
"Since its discovery, the extension has evolved and is currently at version 3.0, based on the internal versioning system. It supports three web browsers and theft of mail from both Gmail and AOL webmail," the researchers informed. By stealing email data in the context of a user's already-logged-in session, the attack is hidden from the email provider, making detection very challenging.
Similarly, the way in which the extension works means suspicious activity would not be logged in a user's email "account activity" status page, were they to review it, the cybersecurity firm noted.
This story has been sourced from a third party syndicated feed, agencies. Mid-day accepts no responsibility or liability for its dependability, trustworthiness, reliability and data of the text. Mid-day management/mid-day.com reserves the sole right to alter, delete or remove (without notice) the content in its absolute discretion for any reason whatsoever