Operation Digital Eye | Chinese APT Compromises Critical Digital Infrastructure via Visual Studio Code Tunnels
ID: 8f278c57-3122-58d3-885b-fde8dfdc5399
STIX ID: report--8f278c57-3122-58d3-885b-fde8dfdc5399
Date Published: 2024-12-10
Date Updated: 2026-07-27
Author: Aleksandar Milenkoski & Luigi Martire (Tinexta Cyber)
Operation Digital Eye was a three-week cyber-espionage campaign (late June–mid July 2024) attributed to a China-nexus actor targeting European B2B IT service providers; attackers gained initial access via SQL injection and deployed a custom PHP webshell (PHPsert), used custom Mimikatz-derived pass-the-hash tools (mimCN family, e.g., bK2o.exe) for lateral movement, and abused Visual Studio Code Remote Tunnels backed by Microsoft Azure and M247 infrastructure for covert C2; the report provides technical malware analysis, TTPs, IOCs (file hashes, IPs, domain), temporal/activity analysis, and discusses probable shared tooling vendors/quartermasters within the Chinese APT ecosystem.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
