Aleksandar Milenkoski, Luigi Martire. (2024, December 10). Operation Digital Eye | Chinese APT Compromises Critical Digital Infrastructure via Visual Studio Code Tunnels. Retrieved February 27, 2025.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors targeted memory from the LSASS process to extract credentials. |
| T1003.002 Security Account Manager |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used `reg save` to retrieve credentials from the Security Account Manager (SAM) database. |
| T1018 Remote System Discovery |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used Ping for reconnaissance. |
| T1021.001 Remote Desktop Protocol |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors moved laterally using RDP. |
| T1027.013 Encrypted/Encoded File |
MalwarePHPsert | PHPsert can use multiple obfuscation techniques including XOR encoding, hexadecimal character representation, string concatenation, and randomized variable names. |
| T1033 System Owner/User Discovery |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used `GetUserInfo` to identify current user information. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors attempted to make filenames appear legitimate by tailoring them to the victim organization. |
| T1059.003 Windows Command Shell |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used `cmd.exe` as a default method of execution for a custom version of Mimikatz named bK2o.exe. |
| T1069.001 Local Groups |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used the local.exe tool to view group memberships. |
| T1070.004 File Deletion |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors deleted files delivered to compromised hosts, often named with the pattern do.* such as do.exe. |
| T1071.001 Web Protocols |
MalwarePHPsert | PHPsert can retrieve remote files using HTTP POST. |
| T1087.001 Local Account |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used the local.exe tool to view local account information. |
| T1098.004 SSH Authorized Keys |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used SSH access enabled by authorized_keys files for remote execution. |
| T1105 Ingress Tool Transfer |
MalwarePHPsert | PHPsert has the ability to retrieve remote payloads. |
| T1106 Native API |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used native API such as `GetUserInfo`. |
| T1132.001 Standard Encoding |
MalwarePHPsert | PHPsert can use Base64-encoded values in C2 communications. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePHPsert | PHPsert has the ability to decode and decrypt obfuscated strings prior to execution. |
| T1190 Exploit Public-Facing Application |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used SQL injection to compromise publicly exposed web and database servers. |
| T1219.001 IDE Tunneling |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors created Visual Studio Code dev tunnels to access targeted endpoints through the browser-based version of Visual Studio Code. |
| T1505.003 Web Shell |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors deployed a PHP-based webshell to maintain persistent access. |
| T1505.003 Web Shell |
MalwarePHPsert | PHPsert can use the .php assert function to execute attacker-provided code and maintain persistence on targeted web servers. |
| T1543.003 Windows Service |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors created a service named Visual Studio Code Service to run Visual Studio code. |
| T1550.002 Pass the Hash |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used a pass-the-hash capability to move laterally. |
| T1569.002 Service Execution |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used the winsw tool to deploy a Visual Studio code executable as a Windows service. |
| T1588.002 Tool |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used third party tools including custom implementations of Mimikatz. |
| T1591 Gather Victim Org Information |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors concealed malicious activity by using terms that aligned with the technological context of the targeted organization. |
| T1614.001 System Language Discovery |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used the local language of targeted organizations to disguise file system activity. |
| T1665 Hide Infrastructure |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used public Cloud infrastructure to mask malicious activity. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.