The Chinese hacking gang , known as Mustang Panda , is incorporating Visual Studio Code software into espionage operations targeting government entities in Southeast Asia.

“This threat actor exploited Visual Studio Code’s built-in reverse shell feature to gain access to target networks,” Tom Fakterman, a researcher with Palo Alto Networks’ Unit 42, said in a report. Describing the technique as “relatively new,” he noted that it first appeared in September 2023 by Truvis Thornton.
See also: Mustang Panda targets Asia with DOPLUGS variant
The campaign appears to be a follow-up to a previous attack targeting an unnamed Southeast Asian government entity, which occurred in late September 2023.
Mustang Panda, also known as BASIN, Bronze President, Camaro Dragon, Earth Preta, HoneyMyte, RedDelta and Red Lich, has been active since 2012, conducting regular cyberespionage targeting government and religious entities across Europe and Asia, with a particular focus on countries in the South China Sea.
The latest series of attacks is notable for its malicious exploitation of Visual Studio Code's reverse shell , which allows for the execution of arbitrary code and the transmission of additional malicious payloads.
“To exploit Visual Studio code for malicious purposes, a hacker can exploit the version of the code.exe file (the Visual Studio executable) or an already installed version of the software,” according to Fakterman. “By running the code.exe tunnel command, the hacker obtains a link that requires them to log in to GitHub with their personal account.”
Once this step is complete, the hacker is redirected to a Visual Studio Code web environment, which is connected to the infected system. This allows them to execute commands or create new files.
Read more: Mustang Panda hackers: They use the new MQsTTang backdoor
It is important to note that the malicious exploitation of this technique was previously identified by Dutch cybersecurity Mnemonic, in connection with the zero-day exploitation of a vulnerability in Check Point's Network Security gateway products (CVE-2024-24919, CVSS score: 8.6).
Unit 42 reported that the Mustang Panda hacking gang used the mechanism to transmit malware, perform reconnaissance, and extract sensitive data. In addition, the hacker allegedly used OpenSSH to execute commands, transfer files, and extend access to the entire network.
But that’s not all. A closer analysis of the infected environment revealed a second cluster of activity occurring simultaneously and, in some cases, even on the same endpoints. This cluster uses the malware , a modular backdoor widely distributed by Chinese espionage gangs.

See also: Visual Studio Code: Flaw allows extensions to steal credentials
At present, it is unclear whether these two sets of attacks are connected or whether two different groups are "interfering with each other's access ."
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: thehackernews
