logo

Threat Actors Weaponizing Visual Studio Code to Deploy a Multistage Malware

ID: 49740625-d14d-5bea-b6a1-fcbeacfa87a4

STIX ID: report--49740625-d14d-5bea-b6a1-fcbeacfa87a4

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-01-19

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Trend Micro and telemetry described a multistage campaign (Evelyn Stealer) that abuses a trojanized Visual Studio Code extension to drop a fake Lightshot DLL, launch staged payloads via hidden PowerShell, inject browsers, harvest credentials, wallets, VPN/Wi‑Fi profiles and sensitive files, compress results, and exfiltrate data to an attacker-controlled FTP server—posing high risk to developers who hold source code and cloud credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.