Sprawling 'Operation Digital Eye' Attack Targets European IT Orgs
ID: bbd54136-166f-521a-b92a-c0a01636db6b
STIX ID: report--bbd54136-166f-521a-b92a-c0a01636db6b
Feed Name: Dark Reading
SentinelLabs identified "Operation Digital Eye," a three-week campaign in late June–July where Chinese-linked actors targeted Southern European B2B IT vendors via SQL injection and PHP web shells, then persisted and exfiltrated credentials using a trojanized Visual Studio Code Remote Tunnels payload (digitally signed 'code.exe') and a modified Mimikatz variant ('bK2o.exe'), likely to enable downstream supply-chain espionage and long-term access while blending attacker traffic with legitimate Azure/GitHub activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
