logo

Operation Digital Eye | Chinese APT Compromises Critical Digital Infrastructure via Visual Studio Code Tunnels

Threat Score
88/100

Date Published: 2024-12-10

Date Updated: 2026-07-27

Author: Aleksandar Milenkoski & Luigi Martire (Tinexta Cyber)

...
...

Operation Digital Eye was a three-week cyber-espionage campaign (late June–mid July 2024) attributed to a China-nexus actor targeting European B2B IT service providers; attackers gained initial access via SQL injection and deployed a custom PHP webshell (PHPsert), used custom Mimikatz-derived pass-the-hash tools (mimCN family, e.g., bK2o.exe) for lateral movement, and abused Visual Studio Code Remote Tunnels backed by Microsoft Azure and M247 infrastructure for covert C2; the report provides technical malware analysis, TTPs, IOCs (file hashes, IPs, domain), temporal/activity analysis, and discusses probable shared tooling vendors/quartermasters within the Chinese APT ecosystem.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.