← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 24, 2026 · 12:17via CyberPress

Kimsuky Hackers Use AI-Generated Chrome Extension to Steal Gmail Data

Brief

North Korea-linked threat actor Kimsuky has been observed targeting organizations in South Korea and Japan with spear-phishing campaigns that combine malicious Windows shortcuts, PowerShell payloads, legitimate remote-access software, and an apparent AI-generated Chrome extension designed to exfiltrate Gmail messages and attachments.

According to ENKI, the campaign highlights how Kimsuky is blending commodity tools with tailored malware to sustain access, collect communications, and reduce the chance of antivirus detection.

The intrusion begins with phishing emails containing OneDrive sharing links to ZIP archives. Those archives contain malicious . lnk shortcut files disguised as documents, including Japanese-language political material and event-related files.

Read more on CyberPress