ATT&CKReferencesZscaler Kimsuky TRANSLATEXT

Zscaler Kimsuky TRANSLATEXT

Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples22

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareTRANSLATEXT

TRANSLATEXT has queried the following registry key to check for installed Chrome extensions: ` HKCU\Software\Policies\Google\Chrome\ExtensionInstallForcelist `.

T1036.005
Match Legitimate Resource Name or Location
MalwareTRANSLATEXT

TRANSLATEXT has been named `GoogleTranslate.crx` to masquerade as a legitimate Chrome extension.

T1041
Exfiltration Over C2 Channel
MalwareTRANSLATEXT

TRANSLATEXT has exfiltrated collected credentials to the C2 server.

T1059.001
PowerShell
MalwareTRANSLATEXT

TRANSLATEXT has used PowerShell to collect system information and to upload the collected data to a Github repository.

T1059.007
JavaScript
GroupKimsuky

Kimsuky has used JScript for logging and downloading additional tools. Kimsuky has used TRANSLATEXT, which contained four Javascript files for bypassing defenses, collecting sensitive information and screenshots, and exfiltrating data.

T1071.001
Web Protocols
MalwareTRANSLATEXT

TRANSLATEXT has used HTTP to communicate with the C2 server.

T1102.001
Dead Drop Resolver
MalwareTRANSLATEXT

TRANSLATEXT has used a dead drop resolver to retrieve configurations and commands from a public blog site.

T1102.001
Dead Drop Resolver
GroupKimsuky

Kimsuky has used TRANSLATEXT and a dead drop resolver to retrieve configurations and commands from a public blog site.

T1102.002
Bidirectional Communication
MalwareTRANSLATEXT

TRANSLATEXT has used a Github repository for C2.

T1102.002
Bidirectional Communication
GroupKimsuky

Kimsuky has used Blogspot pages and a Github repository for C2. Kimsuky has also leveraged Dropbox for downloading payloads and uploading victim system information.

T1112
Modify Registry
MalwareTRANSLATEXT

TRANSLATEXT has modified the following registry key to install itself as the value, granting permission to install specified extensions: ` HKCU\Software\Policies\Google\Chrome\ExtensionInstallForcelist`.

T1113
Screen Capture
GroupKimsuky

Kimsuky has captured browser screenshots using TRANSLATEXT. Kimsuky has also obtained screen captures with custom malware.

T1113
Screen Capture
MalwareTRANSLATEXT

TRANSLATEXT has the ability to capture screenshots of new browser tabs, based on the presence of the `Capture` flag.

T1114
Email Collection
MalwareTRANSLATEXT

TRANSLATEXT has exfiltrated collected email addresses to the C2 server.

T1176.001
Browser Extensions
MalwareTRANSLATEXT

TRANSLATEXT has the ability to capture credentials, cookies, browser screenshots, etc. and to exfiltrate data.

T1185
Browser Session Hijacking
GroupKimsuky

Kimsuky has the ability to use form-grabbing to extract emails and passwords from web data forms.

T1185
Browser Session Hijacking
MalwareTRANSLATEXT

TRANSLATEXT has the ability to use form-grabbing and event-listening to extract data from web data forms.

T1205
Traffic Signaling
MalwareTRANSLATEXT

TRANSLATEXT has redirected clients to legitimate Gmail, Naver or Kakao pages if the clients connect with no parameters.

T1205
Traffic Signaling
GroupKimsuky

Kimsuky has used TRANSLATEXT to redirect clients to legitimate Gmail, Naver or Kakao pages if the clients connect with no parameters.

T1539
Steal Web Session Cookie
MalwareTRANSLATEXT

TRANSLATEXT has exfiltrated updated cookies from Google, Naver, Kakao or Daum to the C2 server.

T1539
Steal Web Session Cookie
GroupKimsuky

Kimsuky has used malware, such as TRANSLATEXT, to steal and exfiltrate browser cookies.

T1555.003
Credentials from Web Browsers
MalwareTRANSLATEXT

TRANSLATEXT has stolen credentials stored in Chrome.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.