North Korea-Linked Hackers Use VS Code Auto-Run
North Korea-linked hackers are employing sophisticated techniques to distribute StoatWaffle malware via Microsoft Visual Studio Code’s auto-run feature. Identified as Team 8, these threat actors leverage the “tasks.json” feature within VS Code to execute malicious code whenever a folder is opened, as reported by NTT Security. These tactics involve using blockchain-related projects as decoys, pulling additional payloads from the web, and executing them silently across various operating systems.
StoatWaffle utilizes a multi-stage infection process. It starts with a Node.js loader that connects with a command-and-control server to receive commands. Subsequently, additional downloaders and modules operate to steal browser credentials, including macOS Keychain data, and even run a remote access trojan for system control. This method allows full data theft and manipulation.
Security experts continue to monitor the advanced methods of North Korea-linked hackers like Team 8. For an in-depth analysis, read the full article here:
North Korea-linked threat actors abuse VS Code auto-run to spread StoatWaffle malware
