ATT&CKCampaignsOperation Digital Eye

Operation Digital Eye

C0061

Campaign, Jun 2024 to Jul 2024.View on attack.mitre.org

About this campaign

Operation Digital Eye was conducted in June and July of 2024 by suspected People's Republic of China (PRC)-nexus threat actors targeting business-to-business IT service providers in Southern Europe. Operation Digital Eye activity included the use of Visual Studio Code tunnels for command and control (C2) and custom lateral movement capabilities. Overlaps in tooling between Digital Eye and previous China-nexus campaigns, Operation Soft Cell and Operation Tainted Love, indicate the potential use of shared vendors or digital quartermasters.

Techniques used22

Procedure examples22

TechniqueProcedure example
T1003.001
LSASS Memory

During Operation Digital Eye, threat actors targeted memory from the LSASS process to extract credentials.

T1003.002
Security Account Manager

During Operation Digital Eye, threat actors used `reg save` to retrieve credentials from the Security Account Manager (SAM) database.

T1018
Remote System Discovery

During Operation Digital Eye, threat actors used Ping for reconnaissance.

T1021.001
Remote Desktop Protocol

During Operation Digital Eye, threat actors moved laterally using RDP.

T1033
System Owner/User Discovery

During Operation Digital Eye, threat actors used `GetUserInfo` to identify current user information.

T1036.005
Match Legitimate Resource Name or Location

During Operation Digital Eye, threat actors attempted to make filenames appear legitimate by tailoring them to the victim organization.

T1059.003
Windows Command Shell

During Operation Digital Eye, threat actors used `cmd.exe` as a default method of execution for a custom version of Mimikatz named bK2o.exe.

T1069.001
Local Groups

During Operation Digital Eye, threat actors used the local.exe tool to view group memberships.

T1070.004
File Deletion

During Operation Digital Eye, threat actors deleted files delivered to compromised hosts, often named with the pattern do.* such as do.exe.

T1087.001
Local Account

During Operation Digital Eye, threat actors used the local.exe tool to view local account information.

T1098.004
SSH Authorized Keys

During Operation Digital Eye, threat actors used SSH access enabled by authorized_keys files for remote execution.

T1106
Native API

During Operation Digital Eye, threat actors used native API such as `GetUserInfo`.

T1190
Exploit Public-Facing Application

During Operation Digital Eye, threat actors used SQL injection to compromise publicly exposed web and database servers.

T1219.001
IDE Tunneling

During Operation Digital Eye, threat actors created Visual Studio Code dev tunnels to access targeted endpoints through the browser-based version of Visual Studio Code.

T1505.003
Web Shell

During Operation Digital Eye, threat actors deployed a PHP-based webshell to maintain persistent access.

View all 22 procedure examples

Attributed groups0

MITRE does not attribute this campaign to a group.

Software4

References1

  1. sentinelone operationDigitalEye Dec 2024 Open source
    Aleksandar Milenkoski, Luigi Martire. (2024, December 10). Operation Digital Eye | Chinese APT Compromises Critical Digital Infrastructure via Visual Studio Code Tunnels. Retrieved February 27, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.