Malicious VS Code on Microsoft Registry Captures Your Screen and Steals Your WiFi Passwords
ID: 3f1403d8-c79b-5c28-af35-ac5704793353
STIX ID: report--3f1403d8-c79b-5c28-af35-ac5704793353
Feed Name: cybersecurityNews.com
A malicious campaign distributed via two Visual Studio Code Marketplace extensions (Bitcoin Black and Codo AI) from the same publisher 'BigBlack' installs an infostealer that captures desktop screenshots, harvests clipboard contents, enumerates running processes, exfiltrates stored WiFi credentials, and hijacks browser sessions by launching Chrome/Edge in headless mode to steal session cookies; the malware achieves persistence and evasion through DLL hijacking of a signed Lightshot binary and signals presence with a mutex named COOL_SCREENSHOT_MUTEX_YARRR, while researchers observed the actor streamlining delivery (moving from passworded ZIPs to direct downloads using native tools like curl).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
