ATT&CKSoftwareTRANSLATEXT

TRANSLATEXT

S1201

Malware.View on attack.mitre.org

About this malware

TRANSLATEXT is malware that is believed to be used by Kimsuky. TRANSLATEXT masqueraded as a Google Translate extension for Google Chrome, but is actually a collection of four malicious Javascript files that perform defense evasion, information collection and exfiltration.

Techniques used15

Procedure examples15

TechniqueProcedure example
T1012
Query Registry

TRANSLATEXT has queried the following registry key to check for installed Chrome extensions: ` HKCU\Software\Policies\Google\Chrome\ExtensionInstallForcelist `.

T1036.005
Match Legitimate Resource Name or Location

TRANSLATEXT has been named `GoogleTranslate.crx` to masquerade as a legitimate Chrome extension.

T1041
Exfiltration Over C2 Channel

TRANSLATEXT has exfiltrated collected credentials to the C2 server.

T1059.001
PowerShell

TRANSLATEXT has used PowerShell to collect system information and to upload the collected data to a Github repository.

T1071.001
Web Protocols

TRANSLATEXT has used HTTP to communicate with the C2 server.

T1102.001
Dead Drop Resolver

TRANSLATEXT has used a dead drop resolver to retrieve configurations and commands from a public blog site.

T1102.002
Bidirectional Communication

TRANSLATEXT has used a Github repository for C2.

T1112
Modify Registry

TRANSLATEXT has modified the following registry key to install itself as the value, granting permission to install specified extensions: ` HKCU\Software\Policies\Google\Chrome\ExtensionInstallForcelist`.

T1113
Screen Capture

TRANSLATEXT has the ability to capture screenshots of new browser tabs, based on the presence of the `Capture` flag.

T1114
Email Collection

TRANSLATEXT has exfiltrated collected email addresses to the C2 server.

T1176.001
Browser Extensions

TRANSLATEXT has the ability to capture credentials, cookies, browser screenshots, etc. and to exfiltrate data.

T1185
Browser Session Hijacking

TRANSLATEXT has the ability to use form-grabbing and event-listening to extract data from web data forms.

T1205
Traffic Signaling

TRANSLATEXT has redirected clients to legitimate Gmail, Naver or Kakao pages if the clients connect with no parameters.

T1539
Steal Web Session Cookie

TRANSLATEXT has exfiltrated updated cookies from Google, Naver, Kakao or Daum to the C2 server.

T1555.003
Credentials from Web Browsers

TRANSLATEXT has stolen credentials stored in Chrome.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Zscaler Kimsuky TRANSLATEXT Open source
    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.