ATT&CKReferencessentinelone operationDigitalEye Dec 2024

sentinelone operationDigitalEye Dec 2024

Aleksandar Milenkoski, Luigi Martire. (2024, December 10). Operation Digital Eye | Chinese APT Compromises Critical Digital Infrastructure via Visual Studio Code Tunnels. Retrieved February 27, 2025.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns1

Procedure examples28

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors targeted memory from the LSASS process to extract credentials.

T1003.002
Security Account Manager
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used `reg save` to retrieve credentials from the Security Account Manager (SAM) database.

T1018
Remote System Discovery
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used Ping for reconnaissance.

T1021.001
Remote Desktop Protocol
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors moved laterally using RDP.

T1027.013
Encrypted/Encoded File
MalwarePHPsert

PHPsert can use multiple obfuscation techniques including XOR encoding, hexadecimal character representation, string concatenation, and randomized variable names.

T1033
System Owner/User Discovery
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used `GetUserInfo` to identify current user information.

T1036.005
Match Legitimate Resource Name or Location
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors attempted to make filenames appear legitimate by tailoring them to the victim organization.

T1059.003
Windows Command Shell
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used `cmd.exe` as a default method of execution for a custom version of Mimikatz named bK2o.exe.

T1069.001
Local Groups
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used the local.exe tool to view group memberships.

T1070.004
File Deletion
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors deleted files delivered to compromised hosts, often named with the pattern do.* such as do.exe.

T1071.001
Web Protocols
MalwarePHPsert

PHPsert can retrieve remote files using HTTP POST.

T1087.001
Local Account
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used the local.exe tool to view local account information.

T1098.004
SSH Authorized Keys
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used SSH access enabled by authorized_keys files for remote execution.

T1105
Ingress Tool Transfer
MalwarePHPsert

PHPsert has the ability to retrieve remote payloads.

T1106
Native API
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used native API such as `GetUserInfo`.

T1132.001
Standard Encoding
MalwarePHPsert

PHPsert can use Base64-encoded values in C2 communications.

T1140
Deobfuscate/Decode Files or Information
MalwarePHPsert

PHPsert has the ability to decode and decrypt obfuscated strings prior to execution.

T1190
Exploit Public-Facing Application
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used SQL injection to compromise publicly exposed web and database servers.

T1219.001
IDE Tunneling
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors created Visual Studio Code dev tunnels to access targeted endpoints through the browser-based version of Visual Studio Code.

T1505.003
Web Shell
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors deployed a PHP-based webshell to maintain persistent access.

T1505.003
Web Shell
MalwarePHPsert

PHPsert can use the .php assert function to execute attacker-provided code and maintain persistence on targeted web servers.

T1543.003
Windows Service
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors created a service named Visual Studio Code Service to run Visual Studio code.

T1550.002
Pass the Hash
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used a pass-the-hash capability to move laterally.

T1569.002
Service Execution
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used the winsw tool to deploy a Visual Studio code executable as a Windows service.

T1588.002
Tool
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used third party tools including custom implementations of Mimikatz.

T1591
Gather Victim Org Information
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors concealed malicious activity by using terms that aligned with the technological context of the targeted organization.

T1614.001
System Language Discovery
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used the local language of targeted organizations to disguise file system activity.

T1665
Hide Infrastructure
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used public Cloud infrastructure to mask malicious activity.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.