The Accidental C2: Exploring Dev Tunnels for Remote Access
ID: 9cc0b354-1995-5cfd-bc88-05c1a73c8c32
STIX ID: report--9cc0b354-1995-5cfd-bc88-05c1a73c8c32
Feed Name: SpecterOps Blog
This blog post analyzes VS Code Dev Tunnels end-to-end and shows that the service's multi-layered protocol (REST discovery and token issuance, WebSocket relay, SSH-over-WebSocket, and MsgPack RPC) can be leveraged as a command-and-control framework. The author details authentication flows (GitHub and Azure/Entra), exposes RPC commands that allow remote spawn/fs/sys operations, provides a PoC tool (Ouroboros), and highlights attack techniques including device-code phishing, refresh-token pivoting (FOCI/BroCI), theft of stored API tokens, persistence, and lateral movement opportunities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
