HomeLatest NewsIndustryNorth Korean cyber attackers use ‘SharpTongue’ spyware to hack into Gmail accounts

North Korean cyber attackers use ‘SharpTongue’ spyware to hack into Gmail accounts

‘SharpTongue’ spyware programme is targeting and victimising individuals working for organisations in the United States, Europe and South Korea.

Preferred Source of Google

In the latest spyware attacks, operated from North Korea, hackers are using malicious Google Chrome or Chromium-based Edge extension to hack into user email accounts.

According to the latest reports, the malicious extension by the hacker group titled ‘SharpTongue’ is capable of stealing email content from and AOL, according to cybersecurity firm Volexity.

“This actor is believed to be North Korean in origin and is often publicly referred to under the name Kimsuky. The definition of which threat activity comprises Kimsuky is a matter of debate among threat intelligence analysts,” a cybersecurity research platform said.

Advertisement
National DefTech Summit
National DefTech Summit
Featuring keynotes, expert panels, live tech demos and strategic networking, the summit will drive actionable insights for defence sector.
Register Now →
Infosec Reimagined
Infosec Reimagined
Infosec Reimagined 2026 is the premier information security summit where top leaders—CISOs, CROs, CIOs, CTOs and risk executives—converge to redefine cyber resilience.
Register Now →
Digital Senate
Digital Senate
Digital Senate is a premier conference uniting government leaders, technologists and innovators to share ideas, success stories and strategies on digital governance, public sector transformation, cybersecurity and emerging technologies in India.
Register Now →
CIO Prism
CIO Prism
CIO Prism unites forward-thinking technology leaders to exchange transformative insights, shape digital strategies, and foster innovation, empowering enterprises to excel in an era of rapid technological change.
Register Now →

As per reports ‘SharpTongue’ spyware programme is targeting and victimising individuals working for organisations in the , Europe and South Korea who work on topics involving North Korea, issues, weapons systems, and other matters of strategic interest to North Korea.

Within the last year, Volexity has responded to multiple incidents involving SharpTongue and, in most cases, has discovered a malicious Google Chrome or Microsoft Edge extension dubbed as ‘SHARPEXT’.

“Since its discovery, the extension has evolved and is currently at version 3.0, based on the internal versioning system. It supports three web browsers and theft of mail from both Gmail and AOL webmail,” the research platform said.

Advertisement

By stealing email data in the context of a user’s already-logged-in session, the attack is hidden from the email provider, making detection very challenging.

Similarly, the way in which the extension works means suspicious activity would not be logged in a user’s email ‘account activity’ status page, were they to review it, the cybersecurity firm noted.

NEWSLETTERThe Daily BriefingThe day's top enterprise technology stories, curated by our editors. Monday to Friday.

Free. One-click unsubscribe anytime. We never share your email.

Tech Observer Desk
Tech Observer Desk
Tech Observer Desk at TechObserver.in is a team of technology reporters led by a senior editor who brings latest updates and developments from the world of technology.
Advertisement
- Advertisement -
- Advertisement -

Dyson launches V16 Piston Animal vacuum in India at ₹79,900

Dyson’s ₹79,900 V16 Piston Animal brings stronger suction, automatic floor sensing, anti-tangle cleaning and a dust-compacting bin to its premium cordless range.

RELATED ARTICLES