Seeing that two-stage certification also involves various technology manufacturers and services, the detection mechanism for activities of unknown locations and devices is becoming more and more complete. Monitoring methods to steal email accounts and read related content through phishing are becoming more and more difficult. However, the road does not turn around and people (hackers) turn around. Recently, security professionals have caught a malicious program that is still in its early stages developed by SharpTongue/Kimsuky, a hacker group suspected of being supported by North Korea. By installing browser extensions/add-ons/plug-ins that usually appear to be relatively harmless, it can monitor and even steal the contents of emails and attachments without logging into the victim’s account.
Because there is no login warning, this method makes it easier for people to “transport” sensitive information without knowing it (surprise, but my mailbox is full of spam). Continue reading The new Gmail monitoring method no longer insists on stealing accounts, but instead uses Chrome / Edge browser extensions to “transport” the content of your mail reports.

▲Image source: ArsTechnica
The new Gmail monitoring method no longer insists on stealing accounts, but instead “ports” your information through Chrome/Edge browser extensions
Although everyone may want to say, I just don’t want to randomly install extensions for browsers developed based on Chromium. But the method of “this” malicious program is actually quite clever. Basically, you may trigger this malicious program called “SHARPEXT” by accidentally opening certain files while surfing the Internet or receiving emails.

It doesn’t make you feel anything, or rather, it just hopes that you and your email service provider won’t notice it at all – the reason why the latter can be bypassed is actually very simple, because you have logged in to the service normally in the browser. Gmail and AOL email services currently listed as targets by SHARPEXT naturally have no control over what you read when you are using your browser to view emails.
After SHARPEXT installs the browser extension, it will also monitor your browser by replacing the browser’s configuration file and executing additional scripts. The technology involved is actually quite complicated and sophisticated. When it replaces the settings file, the Chromium series browser itself has a countermeasure mechanism – it will remind the user that the developer-related settings have been turned on, and ask if they want to turn it off.

However, SHARPEXT will also attempt to obtain information that circumvents these mechanisms so that users are not aware of these warning windows. Because these mechanisms are actually quite complex, the security company Volexity was able to catch this way of stealing information before the hacker organization was perfected.
Experts pointed out that although “currently” SHARPEXT only targets the Windows version of Chrome, Edge and the Whale browser, which is also developed based on Chromium. And at present, it should mainly monitor the United States, Europe and South Korea for strategically related issues such as nuclear bomb weapon systems to steal information from the contents of letters and attached files. However, you must know that they judge that SHARPEXT is still in a very early stage with many bugs (that is why it will be caught).

It is unknown whether the hacker organization will expand the scope of monitoring keywords or turn to other browsers and other targets. But at least experts believe that there is no reason why SHARPEXT cannot cope with browser development on macOS or Linux. So far, in addition to being careful not to open files or installation files from unknown sources, Volexity also provides a mechanism to detect SHARPEXT-related activities and block the destination of the returned information first. For detailed information about SHARPEXT, please refer to Volexity’s websiteThere are detailed instructions.
Further reading:
Gorson shares the behind-the-scenes story of the new song “Somebody Else” using iPhone 13 Pro Max to challenge underwater shooting (Interview)
Source: KOCPC Chinese