Microsoft VS Code Undermined in Asian Spy Attack
ID: 63739cc3-d030-55c1-9c32-ca523229eea6
STIX ID: report--63739cc3-d030-55c1-9c32-ca523229eea6
Feed Name: Dark Reading
Threat Score
Palo Alto Networks' Unit 42 observed Mustang Panda abusing Visual Studio Code's Tunnel feature—effectively turning a signed VS Code binary into a reverse-shell—to perform reconnaissance, drop malware, and exfiltrate data from a Southeast Asian government target; investigators also found concurrent use of imecmnt.exe DLL sideloading to deploy the ShadowPad backdoor, suggesting overlapping or coordinated intrusions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
