Python-Based Malware Slithers Into Systems via Legit VS Code
ID: df2619f1-22dc-50a6-94eb-c065766db0b0
STIX ID: report--df2619f1-22dc-50a6-94eb-c065766db0b0
Feed Name: Dark Reading
Date Published: 2024-10-02
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Researchers from Cyble CRIL uncovered an ongoing Mustang Panda APT campaign that begins with a malicious .lnk file delivering a Python distribution which installs a script that checks for VS Code, deploys the VS Code CLI if needed, and abuses VS Code Remote Tunnels plus GitHub authentication to create a persistent remote tunnel for unauthorized access, data collection, and further malware deployment; the script was initially undetected on VirusTotal and defenders are advised to use behavioral endpoint protections, review scheduled tasks, restrict install permissions, and train users against suspicious files.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
