Visual Studio Code Abused in Sophisticated Multistage Malware Attacks
ID: c2188acc-ec73-5257-80b0-0b5a89b159bd
STIX ID: report--c2188acc-ec73-5257-80b0-0b5a89b159bd
Feed Name: GBHackers
**Executive summary:** The Evelyn Stealer campaign weaponizes seemingly legitimate Visual Studio Code extensions (e.g., themes and AI assistants) to run PowerShell/batch stagers that sideload a trojanized Lightshot DLL, deploy a process-hollowing second stage (iknowyou.model) which decrypts and runs the Evelyn Stealer payload, performs extensive anti-analysis checks, harvests browser credentials, cookies, clipboard, wallet data and system artifacts, packages them into contextual ZIPs, and exfiltrates data over FTP — posing a high risk to developer systems, source code, secrets, and enterprise CI/CD pipelines.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
