From Extension to Infection: An In-Depth Analysis of the Evelyn Stealer Campaign Targeting Software Developers
ID: 2230127e-b310-5a4f-a7e7-4b8f92926e0e
STIX ID: report--2230127e-b310-5a4f-a7e7-4b8f92926e0e
Feed Name: TrendAI Security Blog
This report analyzes the Evelyn Stealer campaign that delivered a multi-stage infostealer through malicious Visual Studio Code extensions: a Lightshot.dll downloader loads a second-stage process-hollowing injector (iknowyou.model) which decrypts and injects the EvelynStealer payload into grpconv.exe; the final stealer uses multiple anti-analysis checks, collects credentials, wallets, clipboard and Wi‑Fi data, and exfiltrates archives over FTP to attacker servers. The report includes technical details (AES key/IV, mutex and process injection behavior), hunting queries, and IoCs (file hashes and C2 domains) to support detection and remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
