<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

North Korean Hackers Exploit VS Code to Remotely Control Victims' Computers

North Korean hackers exploit VS Code tunneling to infiltrate South Korean systems, bypassing security with clever spear-phishing tactics.
Content Team

North Korean hackers are using a clever new trick to break into South Korean systems by exploiting Microsoft Visual Studio Code's legitimate tunneling feature. Darktrace researchers discovered the spear-phishing campaign targeting South Koreans with fake government emails about graduate school programs.

The malicious documents, disguised as official files, secretly install VS Code and create a tunnel called "bizeugene" that gives attackers full remote access. This method bypasses traditional security measures since it uses trusted Microsoft infrastructure instead of suspicious command-and-control servers.

The attack represents a shift toward "living-off-the-land" tactics, where hackers abuse legitimate tools rather than custom malware, making detection extremely difficult for security teams.

Source: Dark Reading

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo