HomeSecurityHackers are abusing VS Code extensions to develop Ransomware

Hackers are abusing VS Code extensions to develop Ransomware

North Korean hackers are evolving their attack strategies using VS Code extensions, which target developers as infection channels.

See also: New 'SleepyDuck' malware on Open VSX allows remote control of Windows

VS Code extensions
Hackers are abusing VS Code extensions to develop Ransomware

Recent security discoveries reveal that the Kimsuky, a state-sponsored group active since 2012, is using JavaScript-based malware to infiltrate systems and create persistent command and control infrastructures, via VS Code extensions.

The threat group has traditionally focused on espionage operations against government entities, think tanks, and special interest groups, but this latest campaign shows the expansion of their technical capabilities and the sophistication of their supply chain targeting.

The attack chain begins with a simple but effective delivery mechanism: a JavaScript file named Themes.js that acts as an initial loader. Unlike heavily disguised malware, this sample uses simple code wrapped in a try-catch block, prioritizing functionality over stealth.

The file initiates contact with an adversary-controlled infrastructure hosted at medianewsonline[.]com, a domain infrastructure service that allows threat actors to create subdomains for malicious purposes. This infrastructure choice reflects the attacker's understanding of legitimate hosting services that often enable or bypass security systems.

Security researchers at Pulsedive noted the complexity of the attack's multi-stage architecture when analyzing the infection chain. The malware operates through a payload delivery system that downloads and executes components sequentially.

The initial JavaScript file sends a GET to iuh234[.]medianewsonline[.]com/dwnkl.php, passing the name of the compromised computer and a hardcoded authentication key. This identification phase allows attackers to identify high-value targets before deploying additional payloads to selected systems.

See also: Open VSX: Addresses Token leaks and malicious extensions

Hackers are abusing VS Code extensions to develop Ransomware
Hackers are abusing VS Code extensions to develop Ransomware

The second stage represents the backbone of the reconnaissance campaign, collecting critical system information for further exploitation. When the C2 server responds to the initial GET request, it delivers another JavaScript payload containing five functions that systematically record the environment of the infected system.

The malware executes commands to collect system information, including hardware specifications and network configuration details. It then retrieves a complete list of all running processes, providing attackers with information about installed security software and legitimate applications that may interfere with the execution of the payload. The reconnaissance phase also records files in the C:\Users, targeting user profiles and potentially identifying valuable data or configuration files.

The output of each command is packaged into cabinet (.cab) and exported via POST requests to the same C2 server. The malware demonstrates technical sophistication by modifying the HKCU\Console\CodePage to UTF-8, ensuring proper text handling during data collection. Temporary files are systematically deleted after export, implementing basic business security practices that prevent forensic analysis.

Persistence mechanisms reveal the attackers’ commitment to long-term access. The malware writes to the %APPDATA%\Microsoft\Windows\Themes\Themes.js and creates a scheduled task named Windows Theme Manager that runs the JavaScript dropper every minute using wscript.exe. This approach leverages legitimate Windows programming utilities to maintain command-and-control connectivity without requiring elevated privileges, making detection more difficult for defenders who rely on privilege escalation notifications.

See also: 12 malicious extensions in VSCode Marketplace steal data

Hackers are abusing VS Code extensions to develop Ransomware
Hackers are abusing VS Code extensions to develop Ransomware

The final stage of the campaign introduces a Word document delivery component, potentially acting as social engineering bait.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS