Campaign, Jun 2024 to Jul 2024.View on attack.mitre.org
Operation Digital Eye was conducted in June and July of 2024 by suspected People's Republic of China (PRC)-nexus threat actors targeting business-to-business IT service providers in Southern Europe. Operation Digital Eye activity included the use of Visual Studio Code tunnels for command and control (C2) and custom lateral movement capabilities. Overlaps in tooling between Digital Eye and previous China-nexus campaigns, Operation Soft Cell and Operation Tainted Love, indicate the potential use of shared vendors or digital quartermasters.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
During Operation Digital Eye, threat actors targeted memory from the LSASS process to extract credentials. |
| T1003.002 Security Account Manager |
During Operation Digital Eye, threat actors used `reg save` to retrieve credentials from the Security Account Manager (SAM) database. |
| T1018 Remote System Discovery |
During Operation Digital Eye, threat actors used Ping for reconnaissance. |
| T1021.001 Remote Desktop Protocol |
During Operation Digital Eye, threat actors moved laterally using RDP. |
| T1033 System Owner/User Discovery |
During Operation Digital Eye, threat actors used `GetUserInfo` to identify current user information. |
| T1036.005 Match Legitimate Resource Name or Location |
During Operation Digital Eye, threat actors attempted to make filenames appear legitimate by tailoring them to the victim organization. |
| T1059.003 Windows Command Shell |
During Operation Digital Eye, threat actors used `cmd.exe` as a default method of execution for a custom version of Mimikatz named bK2o.exe. |
| T1069.001 Local Groups |
During Operation Digital Eye, threat actors used the local.exe tool to view group memberships. |
| T1070.004 File Deletion |
During Operation Digital Eye, threat actors deleted files delivered to compromised hosts, often named with the pattern do.* such as do.exe. |
| T1087.001 Local Account |
During Operation Digital Eye, threat actors used the local.exe tool to view local account information. |
| T1098.004 SSH Authorized Keys |
During Operation Digital Eye, threat actors used SSH access enabled by authorized_keys files for remote execution. |
| T1106 Native API |
During Operation Digital Eye, threat actors used native API such as `GetUserInfo`. |
| T1190 Exploit Public-Facing Application |
During Operation Digital Eye, threat actors used SQL injection to compromise publicly exposed web and database servers. |
| T1219.001 IDE Tunneling |
During Operation Digital Eye, threat actors created Visual Studio Code dev tunnels to access targeted endpoints through the browser-based version of Visual Studio Code. |
| T1505.003 Web Shell |
During Operation Digital Eye, threat actors deployed a PHP-based webshell to maintain persistent access. |
MITRE does not attribute this campaign to a group.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.