Threat Actors Weaponizing Visual Studio Code to Deploy a Multistage Malware
## Cybersecurity: Visual Studio Code Exploitation
Cybersecurity: Visual Studio Code Exploitation
Recent developments indicate that threat actors are exploiting Visual Studio Code as a platform to deploy multistage malware. Utilizing the extensive extension ecosystem, these actors are introducing malware into developer environments.
The campaign, identified as Evelyn Stealer, employs a malicious extension to deliver an information-stealing tool through a series of stages. The primary targets are developers, who often have access to source code, cloud platforms, and cryptocurrency assets.
The attack initiates with the installation of a compromised Visual Studio Code extension. This extension secretly deploys a fake Lightshot.dll file, which is triggered by the legitimate Lightshot.exe tool. This process launches a sequence of actions, including fetching additional payloads and executing hidden PowerShell commands, ultimately leading to the deployment of the Evelyn Stealer executable.
Trend Micro analysts have observed that attackers exploit trust within the Visual Studio Code marketplace to execute a complete attack chain, culminating in extensive data theft.
Recent developments indicate that threat actors are exploiting Visual Studio Code as a platform to deploy multistage malware.
The initial stage operates within a malicious Visual Studio Code extension, disguising itself as Lightshot.dll. When a screenshot is captured, it activates the downloader, which executes a hidden PowerShell command. This command retrieves a secondary payload, named iknowyou.model, from a remote domain, which is saved as runtime.exe and executed.
The malware then creates an AppData folder named Evelyn, injects browsers like Edge and Chrome with abe_decrypt.dll, and uploads a compressed archive to an attacker-controlled FTP server.
For organizations, the compromise of a developer's laptop can lead to exposure of sensitive information such as source code, cloud access tokens, and production credentials, resulting in significant security breaches.
The Evelyn Stealer campaign highlights the vulnerabilities within the Visual Studio Code environment and the potential for exploitation. Organizations should prioritize securing developer workstations to mitigate such threats.
Based on reporting by Cyber Security News.
