Kimsuky Campaign Uses a Chrome Extension to Collect Gmail Data
Kimsuky was linked by Enki WhiteHat to a first-half 2026 campaign against targets in South Korea and Japan that used phishing-delivered malware and a Chrome extension to collect Gmail data. Enki said the extension's Korean comments, debugging text, and emoji were indicators consistent with generative-AI assistance, not independent proof of how the code was produced.
Enki WhiteHat linked Kimsuky to a first-half 2026 espionage campaign targeting people in South Korea and Japan. Its Aug. 20 threat-intelligence report describes phishing emails that led victims to OneDrive-hosted archives containing malicious Windows shortcut files, followed by endpoint malware and remote-access tooling.
The campaign also included a malicious Chrome extension designed to collect Gmail information and send it to operator-controlled infrastructure. Enki said the browser component was part of a broader intrusion chain that included local email collection, keylogging, and the abuse of legitimate remote-control software.
Browser collection within a wider intrusion
According to Enki, opening the shortcut file displayed a decoy document while downloading additional code and establishing persistence. The researchers said the operators changed command-and-control infrastructure frequently and used compromised Korean servers, which made tracking more difficult.
The report describes the Gmail extension as collecting information during normal webmail activity. That makes the browser extension a distinct collection path inside an intrusion that already had endpoint access; it does not mean that a browser extension alone explains the whole campaign.
What the AI claim does and does not establish
Enki observed Korean comments, debugging strings, and emoji in the extension's JavaScript and JSON files, and said those markers were consistent with generative-AI assistance. That is a technical assessment about likely code provenance, not independent confirmation of the model, prompt, or development process used by the operators.
For defenders, the report connects phishing-delivered shortcuts, endpoint persistence, remote-access tools, and browser-resident collection in one campaign. The reported evidence supports attention to those layers together while leaving the method of code generation appropriately qualified.
Key Points
- 1Enki WhiteHat linked a first-half 2026 Kimsuky campaign to phishing-delivered malware and a Chrome extension that collected Gmail data.
- 2The report describes browser collection as one component of a broader intrusion that also used endpoint malware and legitimate remote-access tools.
- 3Enki treated Korean comments, debugging text, and emoji as indicators consistent with generative-AI assistance, not direct proof of how the code was made.
Scoring Rationale
The campaign is relevant to teams managing browser-based email and endpoint security because the reported chain combines phishing, endpoint persistence, remote-access tooling, and webmail collection. The available evidence supports careful attribution to Enki's technical assessment rather than an unqualified claim that the extension was AI-generated.
Sources
Public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems

