North Korea-linked threat actors abuse VS Code auto-run to spread StoatWaffle malware

2026-03-24T08:51:53Za30040b0cc52ff8566b17fdd3dd7e3bf3a32980f32288daaf5386ff5c38ec2b3
Aqua SecurityCISAIran-linkedKnown Exploited VulnerabilitiesMOISNasir SecurityOperation AliceOracle Identity ManagerPwn2Own 2025QNAPRussia-linked phishingSignalStoatWaffleTeam 8TeamPCPTelegram C2TrivyVS Code auto-runWhatsAppchild exploitation takedownenergy sector targetinginfostealermalware newslettersupply chain compromisetasks.json

What happened

Multiple high-impact security developments: North Korea-linked Team 8 is spreading StoatWaffle via malicious Visual Studio Code projects that abuse tasks.json auto-run. A Trivy supply-chain compromise pushed TeamPCP infostealer in malicious images (impacted Aqua Security repos). QNAP patched four SD‑WAN/router vulnerabilities demonstrated at Pwn2Own Ireland 2025 (CVE-2025-62843 through CVE-2025-62846). Iran-linked actors (including MOIS-associated activity) are using Telegram as C2 to target dissidents, and a new Iran‑linked group “Nasir Security” is targeting Gulf energy firms. Russia-linked俗

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
a30040b0cc52ff8566b17fdd3dd7e3bf3a32980f32288daaf5386ff5c38ec2b3
Enrichment time
2026-03-24T08:51:53Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.