logo

Njrat Campaign Using Microsoft Dev Tunnels, (Thu, Feb 27th)

ID: 3edeabd8-38d6-5344-96c6-bfc39d6302af

STIX ID: report--3edeabd8-38d6-5344-96c6-bfc39d6302af

Feed Name: SANS ISC Diary

Threat Score
65/100

Date Published: 2025-02-27

Date Updated: 2026-04-19

...
...

Observed NJRat samples abusing Microsoft Dev Tunnels (devtunnels.ms) as C2 reachability: the report lists two SHA256 samples with the same ImpHash, shows devtunnel C2 URLs and an extracted config (including USB propagation capability), and recommends monitoring for devtunnels.ms in DNS logs to detect similar activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.