logo

The Accidental C2 - Exploring Dev Tunnels for Remote Access

ID: 7a7b89ab-f847-55a1-aaca-d74e84996ea3

STIX ID: report--7a7b89ab-f847-55a1-aaca-d74e84996ea3

Feed Name: XPN InfoSec Blog

Threat Score
55/100

Date Published: 2026-05-09

Date Updated: 2026-07-27

...
...

This research dissects the VS Code Dev Tunnels stack (REST management, WebSocket relay, SSH over WebSocket, MsgPack RPC), demonstrates a PoC tool named Ouroboros that can list tunnels and remotely execute commands/read/write files, and highlights abuse scenarios — including GitHub/Azure OAuth token misuse, device-code phishing, and token pivoting via FOCI/BroCI — that enable persistence, lateral movement, and initial access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.