New Chrome malware spies on your Gmail — what to do now

gmail
(Image credit: Shutterstock)

Update: Patch and restart Google Chrome right now!

Gmail users on Google Chrome or Microsoft Edge should be aware of new email-reading malware recently identified by Volexity, which it's named SHARPEXT.

SHARPEXT is thought to come from a hacking group named SharpTongue (or Kimsuky as it's called by other security firms), which is backed by North Korea. It's been active for over a year and has stolen thousands of messages and files from Gmail and AOL email accounts. Currently, SHARPEXT has only been observed in use on Windows devices, though Volexity says it's possible the malware could work on macOS and Linux systems too.

How SHARPEXT infects victim's systems

Malware

(Image credit: solarseven/Shutterstock)

Victims are convinced to open a document containing the malware through spear phishing and social engineering scams. The malware has been seen operating in browser extensions for Chrome, Edge and the Korean browser Naver Whale, which are all based on Google's Chromium platform. It also seems to be aimed at U.S., European and South Korean users, specifically those who work in areas deemed a threat to North Korea, such as nuclear weaponry.

Once installed, the malware then inserts itself through the Preferences and Secure Preferences files within the browser, and then enables its email-reading/downloading abilities, while also hiding any warning windows that could pop up and alert the user that an unverified extension is running on their device.

The extensions that carry SHARPEXT are hard to spot since there's nothing in them that would trigger a response from an antivirus scanner, with the dangerous parts running from a separate server. It's also hard to notice a data theft in progress through SHARPEXT since you'll have already entered your credentials to access your email, allowing the extension to check and copy data as you view it.

Protecting yourself from this email-reading malware

If you're worried you or someone you know is at risk from this malware, Volexity has put together a list of indicators of compromise (IOCs) on Github that can be used to identify if a machine's been infected. Otherwise, you can double-check which browser extensions you're using, particularly if any can't be found on the Chrome Web Store or have been installed in unusual ways, and remove any that look suspicious. You should also ensure you've got one of the best antivirus software programs installed to add some extra protection to your devices.

Next: Google search just got a big upgrade that speeds up searches. And you can try it now. 

Richard Priday
Assistant Phones Editor

Richard is based in London, covering news, reviews and how-tos for phones, tablets, gaming, and whatever else people need advice on. Following on from his MA in Magazine Journalism at the University of Sheffield, he's also written for WIRED U.K., The Register and Creative Bloq. When not at work, he's likely thinking about how to brew the perfect cup of specialty coffee.

Read more
and image of the Google Chrome logo on a laptop
Over 600,000 Chrome users at risk after 16 browser extensions compromised by hackers — what you need to know
and image of the Google Chrome logo on a laptop
Billions of Chrome users at risk from new browser-hijacking Syncjacking attack — how to stay safe
and image of the Google Chrome logo on a laptop
Google Chrome at risk from shape-shifting browser extensions — how to stay safe
and image of the Google Chrome logo on a laptop
Popular Chrome extensions hijacked by hackers in widespread cyberattack — 3.2 million at risk
A laptop displaying the Chrome logo
Don't click this — malicious ads impersonating Google Chrome spreading dangerous malware
A hacker typing quickly on a keyboard
Hackers are posing as Apple and Google to infect Macs with malware — don’t fall for these fake browser updates
Latest in Malware & Adware
Green skull on smartphone screen.
Malicious Android apps with 60 million installs bombarding phones with ads and phishing attacks — how to stay safe
Malware
Dangerous new password-stealing trojan automatically reinstalls itself on infected PCs
An FBI agent typing on a computer
FBI issues warning to millions of Americans to avoid these websites that can steal your passwords and banking info
A hacker typing quickly on a keyboard
New MassJacker malware is hijacking digital wallets to steal large sums from users
A person trying to set up a new Wi-Fi router
Thousands of TP-Link routers have been infected by a botnet to spread malware
A smartphone screen displaying the Android name and logo next to a sign reading 'MALWARE'.
Fake Google Play Store pages are spreading Trojan malware that can steal your financial data
Latest in News
OnePlus 13 back, leaning against blue wall
OnePlus 13T could come with an even bigger battery than OnePlus 13 — this is incredible
Apple Watch Ultra 2
Apple Watch Ultra 3 just tipped for two major upgrades
NYTimes Connections
NYT Connections today hints and answers — Tuesday, March 25 (#653)
Titus Welliver in Bosch Legacy season 3
‘Bosch’ season 3 preview: 5 things to know before the final season on Prime Video
A first look at Amazon's Fallout TV series coming to Prime Video
‘Fallout’ season 3 plans are reportedly being made — while season 2 is still filming
Surface Laptop 7 from the front
Amazon just gave Surface Laptop 7 a 'frequently returned' label — here's what's going on