Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

SHARPEXT was a browser extension that Volexity said let North Korean-linked attackers inspect and steal email from webmail accounts while victims were already signed in. Instead of taking a password and logging in separately, it operated in the victim’s authenticated browser session—an approach Volexity said could evade ordinary account-activity visibility.

What SHARPEXT did

Volexity’s July 28, 2022 technical report described SHARPEXT as a post-compromise espionage tool. Its key feature was not conventional password theft: it read and exfiltrated webmail as the victim browsed an account that was already logged in. Volexity summarized the distinction this way: “Rather, the malware directly inspects and exfiltrates data from a victim’s webmail account as they browse it.”

Google Threat Analysis Group (TAG) independently described SHARPEXT parsing mail from active Gmail or AOL tabs and exfiltrating it. Volexity reported Gmail and AOL support and compatibility with three browsers, naming Chrome and Edge. These are historical capabilities reported in 2022, not a current compatibility list; the available reporting does not establish later versions or present-day activity.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the attack worked

Volexity said it began observing the previously undocumented malware family in September 2021. It described SHARPEXT as a tool used after attackers had gained access to a victim’s computer. The attackers acquired files needed for deployment, manipulated browser Security Preferences files, and used a script to install the extension.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Once in place, the extension could access email in the browser’s active, authenticated session. That matters because the activity did not require the attacker to sign in to the account from a separate device using stolen credentials. Volexity said this made detection by email providers very difficult and that the activity would not appear on the user’s account-activity page. As the firm put it in its Conclusion & Mitigations section: “By stealing email data in the context of a user’s already-logged-in session, the attack is hidden from the email provider, making detection very challenging.”

Who Volexity linked to the operation

Volexity attributes the activity to the North Korean-linked actor it tracks as SharpTongue. It notes that public reporting often uses the name Kimsuky, but warns that the labels do not map neatly onto one another: the scope of “Kimsuky” is debated, and some activity other sources group under that name does not map back to Volexity’s SharpTongue cluster. MITRE ATT&CK’s Kimsuky group page provides broader group and technique context, but does not by itself establish that every activity attributed to Kimsuky is SharpTongue activity.

Rank #2
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Volexity said it frequently observed SharpTongue targeting people at organizations in the United States, Europe, and South Korea who worked on North Korea, nuclear issues, weapons systems, and other topics of strategic interest to North Korea. A 2023 United Nations Security Council Panel of Experts report also describes targeting across multiple member states involving organizations concerned with nuclear weapons and other DPRK-priority issues.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What defenders and at-risk users can do

The cited recommendations address different points in the attack chain. They can reduce risk or improve investigation, but none is a guarantee that a device or account is safe.

Rank #3
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

For people at elevated risk

  • Google TAG advises at-risk users to consider enrolling in Google’s Advanced Protection Program, enable Enhanced Safe Browsing in Chrome, and keep devices updated.
  • If an account or device may be compromised, contact your organization’s security team or an incident-response professional. Do not rely only on the email provider’s account-activity page: Volexity said SHARPEXT activity might not appear there.

For organizational security teams

  • Volexity recommends enabling and reviewing PowerShell ScriptBlock logging to aid investigation.
  • Periodically review installed browser extensions on high-risk users’ devices. Pay particular attention to extensions unavailable in the Chrome Web Store or loaded from unusual paths.
  • Volexity’s report includes YARA rules and indicators of compromise that defenders can use as investigative leads.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the reporting establishes—and what it does not

Volexity said its logs showed the attacker successfully stole “thousands of emails from multiple victims.” That is the firm’s qualitative description of observed theft, not a precise count or an estimate of the total number of affected people. The central technical account was published on July 28, 2022; its report that SHARPEXT had reached internal version 3.0 describes the tool at that time, not a verified current version.

The practical lesson is that a clean-looking account-activity page cannot rule out every kind of email compromise. In SHARPEXT’s reported method, the attacker’s access to mail was mediated by the victim’s already-authenticated browser session, so endpoint and extension monitoring mattered alongside account protections.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.