Evelyn Stealer is a Windows information stealer delivered through a multistage campaign that abuses the Visual Studio Code extension ecosystem to target software developers and developer workstations. The malware has been associated with trojanized VS Code extensions that drop an initial downloader component masquerading as a legitimate application library, followed by a second-stage injector that decrypts and hollow-injects the final stealer payload into a legitimate Windows process. This infection chain is designed to blend into normal developer activity while reducing visibility to users and security tooling.
The stealer is notable for extensive anti-analysis and anti-virtualization checks, including debugger, virtual machine, remote desktop, and Hyper-V detection, as well as host-environment profiling such as GPU, hostname, disk, process, and registry inspection. It dynamically resolves Windows APIs and uses process hollowing and DLL injection as core execution and evasion mechanisms. Browser theft operations include terminating active browser processes, relaunching browsers with restrictive command-line flags intended to suppress protections and visibility, and injecting a dedicated browser-decryption component to extract stored credentials and cookies.
Evelyn Stealer collects a broad range of victim data, including browser credentials and session material, cryptocurrency wallet information, clipboard contents, screenshots, installed software, running processes, operating system and host details, sensitive files, VPN configuration, and stored Wi-Fi credentials. Stolen data is staged locally, compressed into an archive, and exfiltrated to attacker-controlled infrastructure over FTP. The campaign has been assessed as particularly dangerous for organizations with software development teams because compromise of a developer endpoint can expose source code access, cloud resources, production credentials, and other high-value enterprise assets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
"Notepad++ Official Update Mechanism Hijacked to Deliver Malware..."; "eScan Antivirus Update Servers Compromised to Deliver Multi-Stage Malware"; "Lazarus Campaign Plants Malicious Packages in npm and PyPI Ecosystems"; "Open VSX Supply Chain Attack..."; "Malicious Chrome Extensions..."
The malware constructs an extensive command line with more than 15 browser flags, specifically designed to minimize detection and forensic traces
Upon execution of Evelyn Stealer, the malware dynamically resolves all Windows APIs needed for malware operations, including process injection, file operations, registry access, network communication, and clipboard access.
Once the malware acquires abe_decrypt.dll, the malware targets browsers by implementing a process creation and DLL injection technique specifically designed to compromise browser security mechanisms.
The second-stage payload of this malware campaign is a process hollowing injector, designed to decrypt and inject a third-stage payload into the legitimate Windows process, “grpconv.exe”.
The malware implements different virtual machine detection methods, debugger detection, and specialized checks for analysis environments like Remote Desktop Protocol (RDP) sessions and Hyper-V.
Additionally, the malware captures desktop screenshots and collects various information from the infected machine, including the following: System information such as username, computer name, OS version, installed software, running processes, sensitive files, VPN configuration, and more
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multi-stage information stealer delivered via weaponized Visual Studio Code extensions targeting software developers. It uses a downloader and injector chain, process hollowing into grpconv.exe, anti-VM/anti-sandbox checks, browser DLL injection to harvest credentials, and steals system information, screenshots, clipboard data, Wi-Fi passwords, and cryptocurrency wallet data before exfiltrating archives over FTP.
Information stealer targeting software developers via weaponized VS Code extensions; exfiltrates developer credentials and cryptocurrency-related data.
Information-stealing malware delivered via trojanized VS Code extensions. Uses a malicious DLL downloader to run hidden PowerShell that fetches a second-stage payload, then decrypts and injects the stealer into a legitimate Windows process (grpconv.exe) in-memory. Collects clipboard data, installed apps, crypto wallets, running processes, screenshots, Wi‑Fi credentials, system info, and browser (Chrome/Edge) cookies and credentials; exfiltrates to a remote server over FTP as a ZIP. Includes anti-analysis/anti-VM checks and manipulates browser execution (headless/disabled logging/extensions) to facilitate credential/cookie theft.
A multistage information stealer delivered via a trojanized Visual Studio Code extension and a sideloading chain involving a fake Lightshot.dll loaded by legitimate Lightshot.exe. It executes hidden PowerShell to fetch additional payloads, then steals browser credentials (passwords/cookies), crypto wallets, messaging sessions, VPN profiles, Wi‑Fi keys, screenshots, system information, and sensitive files, compressing and exfiltrating data via FTP.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.