---
title: "North Korean Hackers Are Reportedly Going After Gmail Accounts"
description: "Hackers are using never-before-seen methods to bypass email security measures to read and download messages and attachments."
date: "2022-08-04"
modified: "2022-08-04"
authors:
  - name: "Noor Al-Sibai"
    job_title: "Senior Staff Writer"
    link: "https://futurism.com/authors/nooralsibai"
url: "https://futurism.com/the-byte/north-korean-hackers-gmail-malware"
categories:
  - "Cybersecurity"
  - "Future Society"
  - "Hacking"
tags:
  - "hackers"
  - "north korea"
  - "phishing"
  - "the digest"
---

# North Korean Hackers Are Reportedly Going After Gmail Accounts

![Hackers are using never-before-seen methods to bypass email security measures to read and download messages and attachments.](<https://futurism.com/wp-content/uploads/2022/08/north-korean-hackers-gmail-malware.jpg>)
*\<em\>Image: Futurism\</em\>*

## Skimming Emails

North Korean hackers are using never-before-seen methods to bypass Google's email security measures to read and download messages and attachments — all without Google detecting it.

They're using simple browser extensions to steal mail data directly, and are reportedly targeting users in the US, Europe, and South Korea, according to a blog post by [cybersecurity firm Volexity](<https://www.volexity.com/blog/2022/07/28/sharptongue-deploys-clever-mail-stealing-browser-extension-sharpext/>) — sophisticated attacks that could set a jarring precedent.

While these sorts of attacks, known as "spear phishing," have required unwitting users to voluntarily download rogue browser extensions in the past, these attacks are different, because the malware involved can download itself onto target computers without the victims knowing.

Worse yet, Google and Microsoft's browsers are unable to detect that they've been infiltrated by bad actors.

The malware has also steadily evolved since its discovery, Volexity notes, and is already in its third version.

## Window Me This

In [an email to *Ars Technica*](<https://arstechnica.com/information-technology/2022/08/north-korea-backed-hackers-have-a-clever-way-to-read-your-gmail/>), Volexity noted that the current iteration of the attacks dubbed SharpTongue is only affecting Windows users. Volexity President Steven Adair warned, however, that there's no reason MacOS or Linux users couldn't be next.

There's good reason to suggest the hackers are backed by North Korean state actors and affiliated with North Korean hacking group Kimsuky.

Volexity said in its post that it "frequently observes SharpTongue targeting and victimizing individuals working for organizations in the United States, Europe and South Korea who work on topics involving North Korea, nuclear issues, weapons systems, and other matters of strategic interest to North Korea."

In other words, these attacks may be primarily politically motivated, so unless you have sensitive information about the Democratic People's Republic of Korea stored on your computer, you probably don't need to worry.

**READ MORE:** [North Korea-backed hackers have a clever way to read your Gmail](<https://arstechnica.com/information-technology/2022/08/north-korea-backed-hackers-have-a-clever-way-to-read-your-gmail/>) \[*Ars Technica*\]

**More on phishing scams:** [Crypto Fans Are So Dumb They're Clicking .EXE Files Disguised as NFTs](<https://futurism.com/nfts-malware-risk>)

## Author
At Futurism, I've often been drawn to unpacking the narratives that underlie technological, scientific and medical progress, with a special interest in areas of conflict and ambiguity that end up setting agendas and steering the fates of both elites and the hoi polloi. I'm a committed generalist, but I often find myself returning to work involving NASA and the private space sector, the effects of AI on media and society, and the mechanics of the pharmaceutical industry, with a specific focus on the spread of GLP-1 drugs like Ozempic and Wegovy. Prior to Futurism, I worked for publications ranging from Media Matters and Truthdig to Raw Story and Bustle. I'm also the author of "Myspace Scene Queens," a 2024 title in Instar Books' acclaimed "Remember the Internet" series. My work at Futurism has been cited by outlets including the New Yorker, Slate, Nieman Lab, the Verge, the MIT Technology Review, the Sunday Times, and the Daily Beast. I grew up in North Carolina, attended the University of North Carolina at Asheville, and now live in Brooklyn, New York. In my free time, I'm an avid reader and music fan; you can probably find me at a local poetry reading, concert, underground rave, or DJ set. I'm the proud parent of an ineffable orange cat named Mee-Mow.

### Author social links  
[Bluesky](<https://bsky.app/profile/noorfromfuturism.bsky.social>)