LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S1201: TRANSLATEXT

TRANSLATEXT is malware that is believed to be used by Kimsuky.[1] TRANSLATEXT masqueraded as a Google Translate extension for Google Chrome, but is actually a collection of four malicious Javascript files that perform defense evasion, information collection and exfiltration.[1]

EnterpriseS1201MalwareObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

TRANSLATEXT matters because it is described as Windows malware masquerading as a Google Translate Chrome extension while performing collection, evasion, command-and-control, and exfiltration behaviors. For leaders, the practical issue is not only malware on an endpoint; it is loss of trust in the browser as an identity and SaaS access point, with potential exposure of email, web sessions, screenshots, browser-stored credentials, and session cookies.

Executive priority

Prioritize this as a browser, identity, and endpoint governance problem. Executives should ask whether the organization can prove which browser extensions are allowed, whether suspicious extension activity is visible to the SOC, and whether incident responders can quickly invalidate web sessions and assess email or SaaS exposure. The relationship to Kimsuky is described by ATT&CK as believed use, so it should inform threat intelligence context without being treated as confirmed attribution in local incidents.

Technical view

ATT&CK provides no official detection text for TRANSLATEXT, so coverage should be validated through its related behaviors: Chrome/browser extension persistence, PowerShell execution, Registry query and modification, browser session hijacking, web cookie and browser credential access, screen capture, email collection, traffic signaling, web-protocol C2, dead-drop resolver use, bidirectional web-service communication, and exfiltration over C2. SOC and IR teams should confirm visibility on Windows endpoints where Chrome extensions can be installed and where browser identity artifacts may be accessed.

Likely telemetry

  • Windows endpoint process telemetry, especially PowerShell execution and child processes from browser contexts
  • Windows Registry query and modification events
  • Chrome extension inventory, installation source, extension file changes, and policy state
  • Browser file access telemetry for credential stores, cookies, session data, and extension directories
  • Network telemetry for unusual HTTP/S or web-service communication from endpoints or browser processes

Detection direction

  • Start with extension governance: identify unauthorized or locally installed Chrome extensions, especially those impersonating common productivity utilities such as translation tools.
  • Tune detections for suspicious PowerShell use associated with browser, extension, or user-profile paths; account for administrative scripts to reduce false positives.
  • Correlate Registry discovery/modification with browser extension installation, persistence, and suspicious network activity rather than alerting on Registry activity alone.
  • Look for access to browser credential stores, cookies, and session artifacts followed by outbound web traffic or SaaS/email activity from the same user or host.
  • Treat web-protocol C2 and legitimate web-service abuse as a blind spot: proxy allowlists and TLS encryption may hide command-and-control or dead-drop resolver behavior unless logs include destination, timing, process, and user context.

Mitigation priorities

  • Enforce browser extension allowlisting or managed extension policy for Chrome on Windows endpoints.
  • Reduce browser-stored credential and session risk through identity controls, session management, and rapid session revocation procedures after suspected compromise.
  • Constrain and monitor PowerShell use according to administrative need, with logging sufficient for incident reconstruction.
  • Harden endpoint controls around user-profile browser data, extension directories, and suspicious script execution.
  • Maintain proxy, DNS, endpoint, and identity logging retention sufficient to investigate web-protocol C2, cookie/session theft, and exfiltration over existing channels.
Additional notes and limits

The supplied ATT&CK object identifies TRANSLATEXT as malware believed to be used by Kimsuky and describes it as a malicious Chrome extension masquerading as Google Translate. The strongest defensive value is in validating controls around browser extension governance, browser credential/session protection, Windows endpoint telemetry, and web-based C2/exfiltration visibility.

Official ATT&CK detection guidance is not provided. Tactics are not specified on the malware object itself, so technical direction is inferred only from the supplied relationships to ATT&CK techniques. No claim is made that any environment is exposed or that activity is currently occurring.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

TRANSLATEXT

TRANSLATEXT is malware that is believed to be used by Kimsuky.[1] TRANSLATEXT masqueraded as a Google Translate extension for Google Chrome, but is actually a collection of four malicious Javascript files that perform defense evasion, information collection and exfiltration.[1]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

15 rows
DomainIDNameRelationship / procedure
EnterpriseT1071.001Web ProtocolsSub-technique

TRANSLATEXT has used HTTP to communicate with the C2 server.[1]

EnterpriseT1555.003Credentials from Web BrowsersSub-technique

TRANSLATEXT has stolen credentials stored in Chrome.[1]

EnterpriseT1059.001PowerShellSub-technique

TRANSLATEXT has used PowerShell to collect system information and to upload the collected data to a Github repository.[1]

EnterpriseT1041Exfiltration Over C2 Channel

TRANSLATEXT has exfiltrated collected credentials to the C2 server.[1]

EnterpriseT1112Modify Registry

TRANSLATEXT has modified the following registry key to install itself as the value, granting permission to install specified extensions: ` HKCU\Software\Policies\Google\Chrome\ExtensionInstallForcelist`.[1]

EnterpriseT1185Browser Session Hijacking

TRANSLATEXT has the ability to use form-grabbing and event-listening to extract data from web data forms.[1]

EnterpriseT1102.001Dead Drop ResolverSub-technique

TRANSLATEXT has used a dead drop resolver to retrieve configurations and commands from a public blog site.[1]

EnterpriseT1539Steal Web Session Cookie

TRANSLATEXT has exfiltrated updated cookies from Google, Naver, Kakao or Daum to the C2 server.[1]

EnterpriseT1113Screen Capture

TRANSLATEXT has the ability to capture screenshots of new browser tabs, based on the presence of the `Capture` flag.[1]

EnterpriseT1176.001Browser ExtensionsSub-technique

TRANSLATEXT has the ability to capture credentials, cookies, browser screenshots, etc. and to exfiltrate data.[1]

EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

TRANSLATEXT has been named `GoogleTranslate.crx` to masquerade as a legitimate Chrome extension.[1]

EnterpriseT1114Email Collection

TRANSLATEXT has exfiltrated collected email addresses to the C2 server.[1]

EnterpriseT1102.002Bidirectional CommunicationSub-technique

TRANSLATEXT has used a Github repository for C2.[1]

EnterpriseT1012Query Registry

TRANSLATEXT has queried the following registry key to check for installed Chrome extensions: ` HKCU\Software\Policies\Google\Chrome\ExtensionInstallForcelist `.[1]

EnterpriseT1205Traffic Signaling

TRANSLATEXT has redirected clients to legitimate Gmail, Naver or Kakao pages if the clients connect with no parameters.[1]

Associated objects

Groups, software, and campaigns

GroupEnterprise

G0094: Kimsuky

Kimsuky is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. Kimsuky has focused collection on foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions. Kimsuky operations have overlapped with those of other North Korean state-sponsored cyber espionage actors as a result of ad hoc collaborations or other limited resource sharing.[1][2][3][4][5][6]

Kimsuky was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019).[7][8][9] In 2023, Kimsuky was observed using commercial large language models (LLMs) to assist with vulnerability research, scripting, social engineering and reconnaissance.[10]

DPRK threat actor cluster boundaries overlap in open source reporting, with some security researchers consolidating all attributed North Korean state-sponsored cyber activity under Lazarus Group, rather than tracking operationally distinct subgroups.

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.0
Created
Modified
Raw hash
401ba48159dc1505...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.0Current bundle401ba48159dc…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
  2. [2]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
  3. [3]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
  4. [4]
    mitre-attackS1201
    Open source URL
  5. [5]
    mitre-attackS1201
    Open source URL
  6. [6]
    mitre-attackS1201
    Open source URL
  7. [7]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
  8. [8]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
  9. [9]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
  10. [10]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
  11. [11]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
  12. [12]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
  13. [13]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
  14. [14]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
  15. [15]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
  16. [16]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
  17. [17]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
  18. [18]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
  19. [19]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
  20. [20]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
  21. [21]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
  22. [22]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
  23. [23]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
  24. [24]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
  25. [25]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
  26. [26]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
  27. [27]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
  28. [28]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
  29. [29]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
  30. [30]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
  31. [31]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
  32. [32]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
  33. [33]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
  34. [34]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
  35. [35]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
  36. [36]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
  37. [37]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.