logo

Microsoft VS Code Undermined in Asian Spy Attack

ID: 63739cc3-d030-55c1-9c32-ca523229eea6

STIX ID: report--63739cc3-d030-55c1-9c32-ca523229eea6

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2024-09-13

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Palo Alto Networks' Unit 42 observed Mustang Panda abusing Visual Studio Code's Tunnel feature—effectively turning a signed VS Code binary into a reverse-shell—to perform reconnaissance, drop malware, and exfiltrate data from a Southeast Asian government target; investigators also found concurrent use of imecmnt.exe DLL sideloading to deploy the ShadowPad backdoor, suggesting overlapping or coordinated intrusions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.