The Accidental C2 - Exploring Dev Tunnels for Remote Access
ID: 7a7b89ab-f847-55a1-aaca-d74e84996ea3
STIX ID: report--7a7b89ab-f847-55a1-aaca-d74e84996ea3
Feed Name: XPN InfoSec Blog
Threat Score
This research dissects the VS Code Dev Tunnels stack (REST management, WebSocket relay, SSH over WebSocket, MsgPack RPC), demonstrates a PoC tool named Ouroboros that can list tunnels and remotely execute commands/read/write files, and highlights abuse scenarios — including GitHub/Azure OAuth token misuse, device-code phishing, and token pivoting via FOCI/BroCI — that enable persistence, lateral movement, and initial access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
