Monday, April 14, 2025
Homecyber securityHacker-Attacking Developers Using Weaponized MS Visual Studio

Hacker-Attacking Developers Using Weaponized MS Visual Studio

Published on

SIEM as a Service

Follow Us on Google News

Recent reports suggest that threat actors have been spreading malicious versions of Microsoft Visual Studio, a highly familiar Integrated Development Environment (IDE) used by several developers worldwide.

Recently, cybercriminals have been targeting the familiar IDE, Microsoft Visual Studio, with malicious software. This threat, spread by malicious actors, has been detected and is a cause for concern.

This malicious software delivers a cookie stealer capable of stealing sensitive information like browser cookies containing usernames and passwords.

- Advertisement - Google News

Developers were targeted as they have access to a lot of sensitive information as part of their job, which can be useful for threat actors to access confidential data and spread malware across servers and networks.

Weaponized MS Visual Studio

This malware consists of a filename “VisualStudio[.]exe” and a Visual Studio Folder that contains the Mainproject[.]exe file a.k.a. Information stealing malware. It is a 32-bit GUI-based .NET executable file.

SHA256 hashes:

Visual Studio.exe – 7e8f18c60e35472bf921d3b67fd427933bd150f57d6e83d1472b990a786976db

MainProject.exe – e8a449e692f1b21f1bc4d49d8b27068b03dd7e8df583d429266fdfb261ddeed5

Visual Studio Installer Bundle with Information Stealer Malware

The installation of the VisualStudio[.]exe also simultaneously prompts the installation of Mainproject[.]exe.

If the user permits the Mainproject[.]exe’s installation, the information stealer malware begins to extract information like Machine name, username, processor bit version, operating system version, platform, and IP address.

Once after extraction of system data is done, it proceeds to exfiltrate cookies from browsers like Google Chrome, Firefox, Opera, and Edge.

Furthermore, the cookie stealer targets acquiring the cookies of famous social media platforms and also generates a separate .txt file for these social media credentials.

All this information extracted is stored in the temp folder on the directory where the installation was executed. These data are then transmitted as a .zip file through Telegram designated bot as part of exfiltration.

Exfiltration through Telegram (Source: Cyble)

Once these processes are done, the malware executes the legitimate vs-professional.exe file and deletes the temp folder to hide its track.

Researchers at Cyble have published a complete report about this malware regarding its operation, source code, and other information.

Users of Microsoft Visual Studio (specifically developers) are recommended to take extra precautions when downloading Microsoft Visual Studio from external sites and be vigilant towards this information-stealing malware.

Stay up-to-date with the latest Cyber Security News; follow us on GoogleNewsLinkedinTwitterand Facebook.

Eswar
Eswar
Eswar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.

Latest articles

Slow Pisces Group Targets Developers Using Coding Challenges Laced with Python Malware

A North Korean state-sponsored threat group known as "Slow Pisces" has been orchestrating sophisticated...

DoJ Launches Critical National Security Program to Protect Americans’ Sensitive Data

The U.S. Department of Justice has launched a landmark initiative to block foreign adversaries—including...

FortiGate 0-Day Exploit Allegedly Up for Sale on Dark Web

A chilling new development in the cybersecurity landscape has emerged, as a threat actor...

Alleged FUD Malware ‘GYware’ Advertised on Hacker Forum for $35/Month

A new Remote Access Trojan (RAT) known as "GYware" is being marketed on a...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Slow Pisces Group Targets Developers Using Coding Challenges Laced with Python Malware

A North Korean state-sponsored threat group known as "Slow Pisces" has been orchestrating sophisticated...

DoJ Launches Critical National Security Program to Protect Americans’ Sensitive Data

The U.S. Department of Justice has launched a landmark initiative to block foreign adversaries—including...

FortiGate 0-Day Exploit Allegedly Up for Sale on Dark Web

A chilling new development in the cybersecurity landscape has emerged, as a threat actor...