logo

From Extension to Infection: An In-Depth Analysis of the Evelyn Stealer Campaign Targeting Software Developers

ID: 2230127e-b310-5a4f-a7e7-4b8f92926e0e

STIX ID: report--2230127e-b310-5a4f-a7e7-4b8f92926e0e

Feed Name: TrendAI Security Blog

Threat Score
78/100

Date Published: 2026-01-01

Date Updated: 2026-08-13

...
...

This report analyzes the Evelyn Stealer campaign that delivered a multi-stage infostealer through malicious Visual Studio Code extensions: a Lightshot.dll downloader loads a second-stage process-hollowing injector (iknowyou.model) which decrypts and injects the EvelynStealer payload into grpconv.exe; the final stealer uses multiple anti-analysis checks, collects credentials, wallets, clipboard and Wi‑Fi data, and exfiltrates archives over FTP to attacker servers. The report includes technical details (AES key/IV, mutex and process injection behavior), hunting queries, and IoCs (file hashes and C2 domains) to support detection and remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.