logo

Microsoft Dev Tunnels: Tunnelling C2 and More

ID: c2fb79c7-85d7-50a5-8ec3-131d992b4553

STIX ID: report--c2fb79c7-85d7-50a5-8ec3-131d992b4553

Feed Name: On the Hunt

Threat Score
70/100

Date Published: 2024-11-13

Date Updated: 2026-04-19

Author: Paul Newton

...
...

This report explains how attackers can misuse Microsoft Dev Tunnels to hide command-and-control traffic and create persistent remote access (including RDP/SSH) by leveraging legitimate Microsoft domains and tunneling infrastructure. It includes examples of Cobalt Strike configuration, a PowerShell-based persistence technique using GitHub device authentication, recommended detections (process/module, TLS/domain anomalies, loopback RDP brute-force thresholds), memory forensic guidance, and IOCs such as devtunnel executable and DLL hashes and related domains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.