Hackers Turned Visual Studio Code As A Remote Access Tool
ID: 5e0e72cc-8162-5663-b797-5d5017a7aa58
STIX ID: report--5e0e72cc-8162-5663-b797-5d5017a7aa58
Feed Name: cybersecurityNews.com
This report describes a campaign in which a malicious .LNK file drops an obfuscated Python script that creates persistence via a scheduled task, downloads or uses the VSCode CLI to establish a remote tunnel (leveraging GitHub device activation codes), collects and exfiltrates system data to a C2, and enables attackers to run credential-stealing and reconnaissance tools (e.g., Mimikatz, LaZagne), demonstrating how legitimate developer tooling can be weaponized for unauthorized remote access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
