Kimsuky Uses AI-Generated Chrome Extension to Automatically Steal Gmail Data
Brief
Kimsuky has been linked to a new espionage campaign that turns a Chrome extension into a quiet Gmail collector.
The operation begins with convincing phishing emails and ends with attackers gaining access to messages, attachments, and a victim’s computer. Its mix of browser theft and remote control makes a single opened file especially risky.
The campaign targeted people in South Korea and Japan during the first half of 2026. Victims received a OneDrive sharing link leading to an archive containing a Windows shortcut file, or LNK.
Opening the shortcut displayed a decoy document while a hidden command downloaded more malware and established a foothold. Analysts at Enki identified the activity and linked it to Kimsuky through its tools, targeting, and operating patterns.
