Also known as: tracked as, Sansevieria, mother-in-law's tongue, Medicare Advantage, simply Cobra, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down, MAR reports, HIDDEN COBRA, LAZARUS, Royal Ransomware
WhiteCobra leverages developer ecosystems—particularly Visual Studio Code (VS Code) and the Open VSX Registry—to deliver malware via seemingly legitimate extensions. By manipulating download counts and forging reviews, the actor builds deceptive branding that confers credibility, fooling users into executing code that installs LummaStealer on Windows or other custom payloads on macOS. The monetization model centers on cryptocurrency theft: once credentials or wallet access is extracted, WhiteCobra can transfer stolen funds to controlled infrastructure. The group’s operations exemplify a modern supply‑chain attack strategy: it targets developers who rely on community extensions, provides a convenient attack vector in a high‑traffic marketplace, and quickly adapts by uploading new malicious code every week. Playbooks maintained by WhiteCobra include financial milestones—demonstrating an enterprise‑like approach to threat management—and detail the use of social engineering techniques such as fake branding and review manipulation. While publicly available data confirms malicious activity on VS Code markets, many technical details (e.g., internal command and control architecture) are inferred from broader ATT&CK linkages and analogies to similar groups. Nonetheless, the pattern of monthly or weekly release cadence, targeted developer tooling, and financial outcomes is clear evidence of a deliberate, repeatable campaign.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
WhiteCobra is a financially‑motivated actor that infiltrates software supply chains by publishing malicious extensions on the Visual Studio Code Marketplace and Open VSX registry. The group distributes its own wallet‑stealing malware (LummaStealer) to developers, especially those working with Solidity and other cryptocurrency tooling, and has been linked to a $500k crypto theft in July 2025. WhiteCobra maintains playbooks that specify revenue targets and releases new threats on a weekly cadence, demonstrating persistent and organized operations.
Goals & Targeting
WhiteCobra’s strategic objective is overt financial gain through cryptocurrency theft. By focusing on developers—particularly Solidity programmers working with smart contracts—they exploit the trust inherent in open‑source tooling to obtain privileged credentials or wallet access. The actor seeks high‑volume, low‑effort monetization, targeting a broad array of industries (government, finance, defense, healthcare) across multiple geographies (US, CN, RU, IR, GB, UA, etc.) to diversify risk and maximize opportunity for large payouts.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
WhiteCobra’s activity exhibits consistent, high‑frequency releases—typically one to three new malicious extensions per week—indicating a well‑managed threat infrastructure. The actor prioritizes developer ecosystems for fast, low‑effort compromise and then monetizes through targeted cryptocurrency theft, as demonstrated by the July 2025 $500k takedown. Over time, WhiteCobra has expanded its reach to include not only open‑source markets but also private repositories via automated download scripts and C2 over HTTP/HTTPS with temporary domains derived from patterns like TEMP.* . The lack of overt ransomware activity suggests a focus on “financial theft” rather than extortion. Defensive posturing against WhiteCobra requires understanding their supply‑chain modus operandi: malicious code is stealthily introduced at installation time, and the actor leverages marketplace trust cues to bypass user scrutiny.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is grounded in the Koi Security blog article (https://www.koi.ai/blog/whitecobra-vscode-cursor-extensions-malware) which confirms marketplace infiltration and delivery of LummaStealer. Many aspects—such as cross‑platform targeting, playbook revenue goals, and frequent weekly releases—are extrapolated from that single source; there is minimal corroboration from other publicly available reports. While the identified MITRE techniques are reasonable inferences based on known tactics for marketplace-based attacks, specific evidence for each technique is sparse. Consequently, confidence is moderate regarding core activities (malicious extensions, cryptocurrency theft) but lower for ancillary details like exact tool variants or extended campaign patterns. Sources
No campaigns linked yet.
No observed data linked yet.
17
Techniques
45
Tools
0
Campaigns
40
IOCs
0
Observed Data
12
Tactics