Bitcoin Forum
January 26, 2026, 09:45:50 PM *
News: Latest Bitcoin Core release: 30.2 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Evelyn Stealer: New crypto malware stealer, targets software developer  (Read 40 times)
coinrifft (OP)
Member
**
Offline Offline

Activity: 98
Merit: 41

Learning the process...


View Profile
January 21, 2026, 07:58:58 AM
 #1

Micro Trend published an analysis of a new malware called, Evelyn Stealer. This malware is a information stealer, meaning it gathers data which includes cryptocurrency wallets and other pertinent information to a infected machine.

And this malware targets software developers weaponizing the Microsoft Visual Studio Code (VS Code) extension ecosystem.

Quote
- Analysis of the Evelyn Stealer campaign targeting software developers shows that threat actors are weaponizing the Visual Studio Code (VSC) extension ecosystem to deploy a multistage, information-stealing malware.
-The malware is designed to exfiltrate sensitive information, including developer credentials and cryptocurrency-related data. Compromised developer environments can also be abused as access points into broader organizational systems.
- This activity affects organizations with software development teams that rely on VSC and third-party extensions as well as those with access to production systems, cloud resources, or digital assets.



And so it's a sophisticated attack by the cyber criminals and once you downloaded the malware, it will install a malicious VSC extension and then it executes the payload. And once in execute it will resolves all Windows API needed for the malware to work.

Here is the target crypto wallets:



So if you're a software developer and you are involved in crypto, this is just a warning.

https://www.trendmicro.com/en_us/research/26/a/analysis-of-the-evelyn-stealer-campaign.html
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!