# Fake GoogleTranslate Chrome Extension Enables Remote Browser Control and Credential Theft via Rust Loader, AutoIt, and Stealc v2

> A malicious Chrome extension impersonating Google Translate streams victims' live browser windows to attackers, accepts remote mouse/keyboard input, injects attacker JavaScript, overlays phishing iframes while preserving the real address bar, hijacks proxy settings, and harvests browsing history, bookmarks, extension details, cookies, and credentials. VMRay documented a Rust-loader -> AutoIt -> Stealc v2 infection chain with 4 SHA-256 hashes and 2 live C2 endpoints.

- **Published:** 2026-08-10T00:00:00Z
- **Last reviewed:** 2026-08-10T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1976
- **ID:** TL-2026-1976
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 13 (full data via the Threadlinqs MCP server — Purple tier)

## Description

VMRay researchers documented a malicious Chrome extension impersonating Google Translate that grants attackers near-total remote control of a victim's browser session while simultaneously operating as a credential- and cookie-harvesting platform. The infection chain is three-staged: a Rust-based loader (SHA-256 7ba2c663d76d2d353a02d815381f22a1b04b2032162b1559455d1f456432340a) first executes on the host and deploys an AutoIt script (SHA-256 4f82542f68d2e677fb64ba986c8d5f3a04017a1bf7a11d375e52f950e32eb262), which in turn drops the Stealc v2 information stealer (SHA-256 45c7d791fab4128fb495f359ed641e217883f132bb8f13c1e181caf5f5279a34). The fake GoogleTranslate extension package itself carries SHA-256 02e9da11f035bd4e18338ddd78e2818da49e7d1c8f614e9b329afaf581c33301. The exact distribution vector and the precise filename used for the extension in this campaign were not disclosed in VMRay's reporting and are not asserted here.

Once installed, the extension abuses over-broad Chrome extension API permissions (tab access, scripting, and web-request interception) to give the attacker a real-time view of the victim's Chrome windows plus synthetic mouse-click and keyboard-input capability, deliberately operated in unfocused/background windows so the victim does not notice cursor or window activity. The same permission set is used to inject attacker-controlled JavaScript into visited sites and to render phishing iframes on top of legitimate pages while leaving the real URL bar untouched, a classic man-in-the-browser technique that defeats casual visual inspection. A built-in proxy-hijack capability lets the attacker route the victim's browsing traffic through attacker-controlled infrastructure. In parallel, the extension/Stealc v2 payload collects browsing history, saved bookmarks, installed-extension inventories, cookies, and stored credentials, enabling session/account hijacking independent of the live-control channel. Two HTTP command-and-control endpoints were observed live at the time of the report: 87.120.104[.]147:8080 and 160.20.109[.]33:80.

VMRay's writeup notes that a prior Kimsuky-linked operation used a similarly named extension file, 'GoogleTranslate.crx' -- publicly documented in 2024 as the TRANSLATEXT campaign, which was briefly hosted on a GitHub repository and targeted South Korean academics researching North Korean affairs. That resemblance is naming/branding precedent only: the current campaign carries no confirmed actor attribution, no stated targeting scope, and no evidence tying it to Kimsuky infrastructure or tradecraft beyond the shared lure name. Stealc v2, the terminal payload, is a widely distributed commodity infostealer/loader (introduced March 2025) known industry-wide for a redesigned, RC4-encrypted, JSON-based HTTP C2 protocol, multi-monitor screenshot capture, a unified file grabber, geofenced/HWID-aware payload delivery, and MSI/PowerShell-based delivery options; a Microsoft DCU and Europol operation disrupted over 200 Stealc/Amadey C2 domains and IPs on 2026-06-24, though the family and its affiliates remain active on replacement infrastructure -- consistent with the fresh C2 endpoints seen in this campaign.

## MITRE ATT&CK

- T1059.010 AutoHotKey & AutoIT
- T1176 Software Extensions
- T1036 Masquerading
- T1564.003 Hidden Window
- T1555.003 Credentials from Web Browsers
- T1539 Steal Web Session Cookie
- T1217 Browser Information Discovery
- T1113 Screen Capture
- T1185 Browser Session Hijacking
- T1090 Proxy
- T1071.001 Web Protocols
- T1573.001 Symmetric Cryptography
- T1219 Remote Access Tools

## Sources

- [Fake GoogleTranslate Chrome Extension Lets Attackers Remotely Control Your Browsers](https://cybersecuritynews.com/fake-googletranslate-chrome-extension/)
- [Kimsuky Using TRANSLATEXT Chrome Extension to Steal Sensitive Data](https://thehackernews.com/2024/06/kimsuky-using-translatext-chrome.html)
- [Kimsuky Deploys TRANSLATEXT Chrome Extension Targeting South Korean Academia](https://www.zscaler.com/blogs/security-research/kimsuky-deploys-translatext-target-south-korean-academia)
- [Kimsuky APT Attack Detection: North Korean Hackers Abuse the TRANSLATEXT Chrome Extension to Steal Sensitive Data](https://socprime.com/blog/kimsuky-apt-attack-detection-north-korean-hackers-abuse-the-translatext-chrome-extension-to-steal-sensitive-data/)
- [StealC V2: A Sharper, Stealthier Infostealer Emerges](https://informationsecuritybuzz.com/stealc-v2-a-stealthier-infostealer/)
- [StealC V2 Malware Enhances Stealth and Expands Data Theft Features](https://www.picussecurity.com/resource/blog/stealc-v2-malware-enhances-stealth-and-expands-data-theft-features)
- [I StealC You: Tracking the Rapid Changes To StealC](https://www.zscaler.com/blogs/security-research/i-stealc-you-tracking-rapid-changes-stealc)
- [StealC infrastructure takedown assisted by AI analysis, C2 infiltration](https://www.scworld.com/news/stealc-infrastructure-takedown-assisted-by-ai-analysis-c2-infiltration)
- [StealC and Amadey: Breaking down infostealers and the cybercrime services that deliver them](https://www.microsoft.com/en-us/security/blog/2026/06/24/stealc-and-amadey-breaking-down-infostealers-and-the-cybercrime-services-that-deliver-them/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1976
