logo

Chinese APT Abuses VSCode to Target Government in Asia

ID: cdc638bb-195c-5438-8824-fc6a12ad6231

STIX ID: report--cdc638bb-195c-5438-8824-fc6a12ad6231

Feed Name: Palo Alto Networks Unit 42

Threat Score
85/100

Date Published: 2024-09-06

Date Updated: 2026-04-28

Author: Tom Fakterman

...
...

Unit 42 reports that the Chinese APT Stately Taurus conducted espionage against Southeast Asian government entities by abusing Visual Studio Code’s embedded reverse shell to gain footholds, establish persistence, deliver additional malware and exfiltrate data; a concurrent ShadowPad cluster was observed in the same environment, with overlapping artifacts and extensive credential-theft and lateral-movement activity. The blog provides detailed TTPs, IOCs (hashes and service names), and recommended protections for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.