DPRK Actors Deploy VS Code Tunnels for Remote Hacking
ID: 158b65e8-fbdb-5c40-855f-84eb504bd6f0
STIX ID: report--158b65e8-fbdb-5c40-855f-84eb504bd6f0
Feed Name: Dark Reading
Date Published: 2026-01-22
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
A North Korean-linked spear-phishing campaign targets South Korean recipients with government-themed lures and malicious JSE files disguised as HWPX documents; when opened the files install Visual Studio Code and create a VS Code tunnel (named "bizeugene") that grants attackers interactive remote access via Microsoft's tunneling service. Darktrace researchers documented the LotL technique, historical precedents of VS Code abuse, provided IoCs and MITRE mappings, and recommended defenses such as least privilege, strong access controls, and monitoring of privileged behavior.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
