TRANSLATEXT is a malicious Google Chrome extension associated with the North Korea-linked threat actor Kimsuky. It is designed primarily for browser-based credential and session theft, with functionality focused on harvesting saved Chrome credentials, intercepting data entered into web forms, and stealing updated browser cookies from major Korean and global web services. The extension has been observed masquerading as a legitimate translation-related Chrome add-on to reduce suspicion during installation and use.
Its core tradecraft centers on browser injection and web-form interception. TRANSLATEXT can inject arbitrary JavaScript into targeted pages and has been used to load additional scripts when victims visit selected login portals, enabling theft of usernames and passwords entered into those sites. It also supports form-grabbing and event-listening to capture data submitted through web forms. In addition to credential theft, it exfiltrates browser cookies, enabling follow-on session hijacking against affected web accounts.
The malware uses web-based command-and-control patterns intended to blend with legitimate traffic and complicate blocking. It has used a GitHub repository for command and control and has also employed a dead-drop resolver model in which configuration data and commands are retrieved from a public blog. Collected credentials and cookies are then exfiltrated to attacker-controlled infrastructure. Reporting also attributes to TRANSLATEXT JavaScript components used for defense bypass, sensitive information collection, screenshot collection, and data exfiltration.
TRANSLATEXT targets Windows systems running Google Chrome and fits Kimsuky’s broader pattern of credential collection, browser abuse, and use of trusted web services for covert operations. Its observed targeting of Korean web services is consistent with espionage activity directed at South Korean users and organizations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In 2024, Zscaler discovered a new Google Chrome extension called TRANSLATEXT developed by Kimsuky. This extension can inject arbitrary JS scripts when visiting specific pages. Upon visiting nid.naver.com - the Naver login page - the extension injects auth.js into the browser to steal the login credentials.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
Agent Tesla has the ability to use form-grabbing to extract data from web data forms. Kimsuky has the ability to use form-grabbing to extract emails and passwords from web data forms. TRANSLATEXT has the ability to use form-grabbing and event-listening to extract data from web data forms. XLoader can conduct form grabbing, steal cookies, and extract data from HTTP sessions.
"APT42 has used custom malware to steal login and cookie data from common browsers." / "...extracts the web session cookie and sends it to the C2 server." / "...stole Chrome browser cookies by copying the Chrome profile directories of targeted users."
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
Agent Tesla has the ability to use form-grabbing to extract data from web data forms. Kimsuky has the ability to use form-grabbing to extract emails and passwords from web data forms. TRANSLATEXT has the ability to use form-grabbing and event-listening to extract data from web data forms. XLoader can conduct form grabbing, steal cookies, and extract data from HTTP sessions.
The content repeatedly describes threat actors, malware, and campaigns using HTTP and/or HTTPS for command and control, including examples such as BlackEnergy communicating with C2 over HTTP POST requests and many other families using HTTP/S for C2.
The adversaries had communicated to both Dropbox and Pastebin. APT28 has used Google Drive for C2. APT37 leverages social networking sites and cloud platforms (AOL, Twitter, Yandex, Mediafire, pCloud, Dropbox, and Box) for C2.
...TRANSLATEXT and a dead drop resolver to retrieve configurations and commands from a public blog site.
"APT39 has communicated with C2 through files uploaded to and downloaded from DropBox."; "RIFLESPINE can retrieve C2 commands from an encrypted file on Google Drive then upload the results ... back to Google Drive."; "CloudDuke uses a Microsoft OneDrive account to exchange commands and stolen data"
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malicious Chrome extension that injects JavaScript into targeted pages, including Naver login, to steal credentials.
A malicious Chrome extension that injects JavaScript into targeted pages, including Naver login pages, to steal credentials.
Backdoor that uses a GitHub repository as a command-and-control channel.
Malware that uses a GitHub repository for command and control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.