Threat Actors Weaponizing Visual Studio Code to Deploy a Multistage Malware
ID: 49740625-d14d-5bea-b6a1-fcbeacfa87a4
STIX ID: report--49740625-d14d-5bea-b6a1-fcbeacfa87a4
Feed Name: cybersecurityNews.com
Threat Score
Trend Micro and telemetry described a multistage campaign (Evelyn Stealer) that abuses a trojanized Visual Studio Code extension to drop a fake Lightshot DLL, launch staged payloads via hidden PowerShell, inject browsers, harvest credentials, wallets, VPN/Wi‑Fi profiles and sensitive files, compress results, and exfiltrate data to an attacker-controlled FTP server—posing high risk to developers who hold source code and cloud credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
