Weaponized VS Code Extension “ClawdBot Agent” Spreads ScreenConnect RAT
ID: b32ba48a-53b8-5fbb-a16a-af10cf1caa31
STIX ID: report--b32ba48a-53b8-5fbb-a16a-af10cf1caa31
Feed Name: GBHackers
A malicious VS Code extension impersonating an AI coding assistant ("ClawdBot Agent") was published to the Marketplace and automatically activates at startup to fetch a config that installs a legitimate ConnectWise ScreenConnect client configured to connect to attacker-controlled relays. The operation uses multiple resilient delivery and persistence methods (DLL sideloading via a trojanized DWrite.dll, Dropbox-hosted MSI, hardcoded HTTP fallbacks, and PowerShell scripts), hardcoded C2/relay domains (e.g., clawdbot.getintwopc.site, meeting.bulletmailer.net, darkgptprivate.com), and ties victims to the attacker via embedded keys; the report includes IOCs, install paths (C:\Program Files (x86)\ScreenConnect Client (...)), and remediation guidance including extension removal, uninstalling ScreenConnect, blocking domains/ports, and rotating API keys.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
