Silent Intrusion: VS Code Exploit For Unauthorized Access
ID: ef6027b4-807d-5f4d-96e1-3744aafaf421
STIX ID: report--ef6027b4-807d-5f4d-96e1-3744aafaf421
Feed Name: Cyble Blog
Cyble Research and Intelligence Labs uncovered a sophisticated campaign where a malicious .LNK installer silently deploys an embedded Python runtime and an obfuscated update.py that installs/uses the VSCode CLI to create remote tunnels authenticated via GitHub device activation codes. The malware achieves persistence by creating a scheduled task (MicrosoftHealthcareMonitorNode) that can run with SYSTEM privileges, collects system and user data, exfiltrates information (including the activation code) to a C2 at requestrepo.com, and enables remote file access and command execution; the report includes SHA-256 hashes and URLs as indicators of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
