logo

Chinese hackers use Visual Studio Code tunnels for remote access

ID: 5c694e0c-2cd2-533d-87f8-42ce7eaa40ec

STIX ID: report--5c694e0c-2cd2-533d-87f8-42ce7eaa40ec

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-12-10

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

Operation Digital Eye (June–July 2024) is a targeted espionage campaign observed by SentinelLabs and Tinexta Cyber in which attackers exploited internet-facing services with sqlmap, deployed a PHP webshell (PHPsert), moved laterally using RDP and pass-the-hash with a custom Mimikatz, and established persistent, stealthy backdoors by running a portable Visual Studio Code (code.exe) as a service and abusing VSCode tunnels routed through Microsoft Azure (*.devtunnels.ms), enabling authenticated remote access that evades many security controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.