Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware TRANSLATEXT

TRANSLATEXT

TLP:CLEAR
Family

AI Analysis

· 3 hours ago

Executive Summary

TRANSLATEXT is a phishing‑style Chrome extension used by Kimsuky that masquerades as Google Translate. It injects obfuscated JavaScript to stealthily harvest information and exfiltrate data over standard HTTPS traffic, compromising the confidentiality of user activity on Windows systems.

Enhanced Description

TRANSLATEXT is a malicious Chrome extension that presents itself as the legitimate Google Translate add‑on, exploiting users’ trust in browser extensions to execute its payload on Windows machines. According to multiple security research reports, the package contains four distinct JavaScript files that work together to evade defensive tooling, harvest system information, and exfiltrate data from an infected host. Once installed, TRANSLATEXT remains dormant until a user navigates to websites that trigger its code path, at which point it can dynamically load further scripts or communicate with command‑and‑control infrastructure. The malware’s JavaScript component is heavily obfuscated, making static analysis difficult and allowing it to bypass simple signature‑based detection. Kimsuky, the attribution group linked to TRANSLATEXT, has a history of sophisticated espionage campaigns targeting government and industrial sectors in East Asia. By leveraging the ubiquitous Chrome extension platform, TRANSLATEXT reduces its footprint compared to traditional desktop malware while still enabling remote data exfiltration over normal HTTPS traffic. The primary impact of TRANSLATEXT is informational theft rather than destructive payload delivery. Its ability to collect sensitive web session data, browser history and possibly credentials collected via the spoofed Translate UI makes it a valuable tool for threat actors seeking actionable intelligence from corporate and governmental networks.

Key Capabilities

  • Masquerades as legitimate Google Translate Chrome extension
  • Deploys four malicious JavaScript files for execution
  • Uses heavy code obfuscation to evade signature‑based detection
  • Collects system and browsing information (URL history, cookies, credentials)
  • Exfiltrates data over HTTPS to command & control servers
  • Attempts basic defense evasion by disabling or bypassing browser security warnings

ATT&CK Techniques

T1059.001
T1027
T1074
T1041

Recommended Actions

  • Deploy Chrome Enterprise policies to block installation of unknown extensions or enforce whitelisting only for vetted add‑ons
  • Implement content security policy (CSP) and XSS protection in corporate browsers
  • Enable Windows Defender Application Guard or similar sandboxing options for web browsing
  • Monitor outbound HTTPS traffic from browser processes for anomalous data transfer patterns
  • Use endpoint detection platforms to flag execution of obfuscated JavaScript within Chrome extensions
  • Keep browser and all extensions up to date with the latest security patches

Suggested Tags

Kimsuky
ChromeExtension
JavaScriptMalware
InformationStealer
DefenseEvasion

Confidence Assessment

High confidence in the core description that TRANSLATEXT is a malicious Chrome extension linked to Kimsuky, based on multiple independent vendor reports. However, detailed operational data such as file hashes, precise command‑and‑control domains, persistence mechanisms beyond the extension install, and post‑exfiltration behaviors are not available in the supplied source, limiting full understanding of its life cycle and impact.

Description

TRANSLATEXT is malware that is believed to be used by Kimsuky.(Citation: Zscaler Kimsuky TRANSLATEXT) TRANSLATEXT masqueraded as a Google Translate extension for Google Chrome, but is actually a collection of four malicious Javascript files that perform defense evasion, information collection and exfiltration.(Citation: Zscaler Kimsuky TRANSLATEXT)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.