Executive Summary
TRANSLATEXT is a phishing‑style Chrome extension used by Kimsuky that masquerades as Google Translate. It injects obfuscated JavaScript to stealthily harvest information and exfiltrate data over standard HTTPS traffic, compromising the confidentiality of user activity on Windows systems.
Enhanced Description
TRANSLATEXT is a malicious Chrome extension that presents itself as the legitimate Google Translate add‑on, exploiting users’ trust in browser extensions to execute its payload on Windows machines. According to multiple security research reports, the package contains four distinct JavaScript files that work together to evade defensive tooling, harvest system information, and exfiltrate data from an infected host. Once installed, TRANSLATEXT remains dormant until a user navigates to websites that trigger its code path, at which point it can dynamically load further scripts or communicate with command‑and‑control infrastructure. The malware’s JavaScript component is heavily obfuscated, making static analysis difficult and allowing it to bypass simple signature‑based detection. Kimsuky, the attribution group linked to TRANSLATEXT, has a history of sophisticated espionage campaigns targeting government and industrial sectors in East Asia. By leveraging the ubiquitous Chrome extension platform, TRANSLATEXT reduces its footprint compared to traditional desktop malware while still enabling remote data exfiltration over normal HTTPS traffic. The primary impact of TRANSLATEXT is informational theft rather than destructive payload delivery. Its ability to collect sensitive web session data, browser history and possibly credentials collected via the spoofed Translate UI makes it a valuable tool for threat actors seeking actionable intelligence from corporate and governmental networks.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in the core description that TRANSLATEXT is a malicious Chrome extension linked to Kimsuky, based on multiple independent vendor reports. However, detailed operational data such as file hashes, precise command‑and‑control domains, persistence mechanisms beyond the extension install, and post‑exfiltration behaviors are not available in the supplied source, limiting full understanding of its life cycle and impact.
TRANSLATEXT is malware that is believed to be used by Kimsuky.(Citation: Zscaler Kimsuky TRANSLATEXT) TRANSLATEXT masqueraded as a Google Translate extension for Google Chrome, but is actually a collection of four malicious Javascript files that perform defense evasion, information collection and exfiltration.(Citation: Zscaler Kimsuky TRANSLATEXT)