Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors WhiteCobra

Also known as: tracked as, Sansevieria, mother-in-law's tongue, Medicare Advantage, simply Cobra, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down, MAR reports, HIDDEN COBRA, LAZARUS, Royal Ransomware

Description

WhiteCobra leverages developer ecosystems—particularly Visual Studio Code (VS Code) and the Open VSX Registry—to deliver malware via seemingly legitimate extensions. By manipulating download counts and forging reviews, the actor builds deceptive branding that confers credibility, fooling users into executing code that installs LummaStealer on Windows or other custom payloads on macOS. The monetization model centers on cryptocurrency theft: once credentials or wallet access is extracted, WhiteCobra can transfer stolen funds to controlled infrastructure. The group’s operations exemplify a modern supply‑chain attack strategy: it targets developers who rely on community extensions, provides a convenient attack vector in a high‑traffic marketplace, and quickly adapts by uploading new malicious code every week. Playbooks maintained by WhiteCobra include financial milestones—demonstrating an enterprise‑like approach to threat management—and detail the use of social engineering techniques such as fake branding and review manipulation. While publicly available data confirms malicious activity on VS Code markets, many technical details (e.g., internal command and control architecture) are inferred from broader ATT&CK linkages and analogies to similar groups. Nonetheless, the pattern of monthly or weekly release cadence, targeted developer tooling, and financial outcomes is clear evidence of a deliberate, repeatable campaign.

Goals & Targeting

Targeted Sectors

Government
Financial services
Telecommunications
Defense
Healthcare
Education
Manufacturing
Critical infrastructure
Non profit
Media
Energy
Hospitality
Retail
Pharmaceutical
Aviation
Aerospace
Transportation
Information technology
Think tank
Gaming
Entertainment
Nuclear
Mining
Chemical
Legal services
Maritime
Food agriculture
Construction
Oil gas
Utilities

Targeted Countries / Regions

US
CN
RU
IR
GB
UA
JP
VN
AU
IN
PK
TW
IL
SA
DE
AE
KR
BY
SG
KP
PL
CA
TR
MX
ES
RO
FR
NG
IT
LB
AZ
KZ

AI Analysis

Grounded in web research
· 2 hours ago

Executive Summary

WhiteCobra is a financially‑motivated actor that infiltrates software supply chains by publishing malicious extensions on the Visual Studio Code Marketplace and Open VSX registry. The group distributes its own wallet‑stealing malware (LummaStealer) to developers, especially those working with Solidity and other cryptocurrency tooling, and has been linked to a $500k crypto theft in July 2025. WhiteCobra maintains playbooks that specify revenue targets and releases new threats on a weekly cadence, demonstrating persistent and organized operations.

Goals & Targeting

WhiteCobra’s strategic objective is overt financial gain through cryptocurrency theft. By focusing on developers—particularly Solidity programmers working with smart contracts—they exploit the trust inherent in open‑source tooling to obtain privileged credentials or wallet access. The actor seeks high‑volume, low‑effort monetization, targeting a broad array of industries (government, finance, defense, healthcare) across multiple geographies (US, CN, RU, IR, GB, UA, etc.) to diversify risk and maximize opportunity for large payouts.

Enhanced Description

Key Capabilities

  • Supply–chain compromise via malicious VS Code extensions
  • Social engineering: fake reviews, branding, and click‑throughs
  • Automated weekly threat deployment
  • Revenue‑targeted playbooks
  • Cross‑platform delivery (Windows, macOS)
  • Cryptocurrency wallet theft using LummaStealer

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Exfiltration
Impact

ATT&CK Techniques

T1566.002
T1133
T1190
T1059.001
T1071.001
T1037.003
T1082
T1218.005
T1048.004
T1550.001
T1546.006

Software / Tooling

LummaStealer
Custom VS Code malicious extensions (e.g., Cursor, Cobalt Strike variants)
PowerShell scripts
Cobalt Strike "Cobalt"
BlackBytes/LockBit style backdoors

Campaigns & Victims

WhiteCobra’s activity exhibits consistent, high‑frequency releases—typically one to three new malicious extensions per week—indicating a well‑managed threat infrastructure. The actor prioritizes developer ecosystems for fast, low‑effort compromise and then monetizes through targeted cryptocurrency theft, as demonstrated by the July 2025 $500k takedown. Over time, WhiteCobra has expanded its reach to include not only open‑source markets but also private repositories via automated download scripts and C2 over HTTP/HTTPS with temporary domains derived from patterns like TEMP.* . The lack of overt ransomware activity suggests a focus on “financial theft” rather than extortion. Defensive posturing against WhiteCobra requires understanding their supply‑chain modus operandi: malicious code is stealthily introduced at installation time, and the actor leverages marketplace trust cues to bypass user scrutiny.

IOC Patterns

  • Malicious extensions in Visual Studio Code Marketplace
  • Use of fake reviews / branding for credibility
  • Domain-based C2 using short‑lived temporary domains (e.g., TEMP.*)
  • Downloads via pages.dev or similar third‑party hosts
  • Exfiltration over web services and standard HTTPS traffic

Recommended Actions

  • Implement rigorous vetting for extensions installed in VS Code, including publisher verification and integrity checks. Validate signatures on marketplace downloads; block unsigned or newly published extensions from untrusted vendors. Educate developers about the risks of installing third‑party extensions, especially those with high download counts but low review ratings. Monitor outbound connections to temporary or suspicious domains (e.g., TEMP.*) and employ DLP for cryptocurrency wallet file access. Regularly update VS Code, its plugin ecosystem, and operating systems to patch known vulnerabilities that could be exploited by malicious payloads.

Suggested Tags

APT
Supply‑Chain Attack
Cryptocurrency Theft
Financial Motive
Developer Tools Exploitation

Confidence Assessment

The analysis is grounded in the Koi Security blog article (https://www.koi.ai/blog/whitecobra-vscode-cursor-extensions-malware) which confirms marketplace infiltration and delivery of LummaStealer. Many aspects—such as cross‑platform targeting, playbook revenue goals, and frequent weekly releases—are extrapolated from that single source; there is minimal corroboration from other publicly available reports. While the identified MITRE techniques are reasonable inferences based on known tactics for marketplace-based attacks, specific evidence for each technique is sparse. Consequently, confidence is moderate regarding core activities (malicious extensions, cryptocurrency theft) but lower for ancillary details like exact tool variants or extended campaign patterns. Sources

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 18 Filename 2

References

  1. attack.mitre.org — Cited by web research for: Sandworm Team
  2. unit42.paloaltonetworks.com — Cited by web research for: BlackCat
  3. www.fortinet.com — Cited by web research for: MAR reports
  4. research.checkpoint.com — Cited by web research for: Akira
  5. www.koi.ai — Cited by web research for: zak.eth

Intel Summary

17

Techniques

45

Tools

0

Campaigns

40

IOCs

0

Observed Data

12

Tactics

Tags

Ransomware
Financial Targeting
Critical Infrastructure
Advanced Persistent Threat (APT)
Cryptocurrency
Malware Distribution
Social Engineering
APT
Supply‑Chain Attack
Cryptocurrency Theft
Financial Motive
Developer Tools Exploitation

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.