Operation Digital Eye is a suspected China-nexus cyberespionage activity cluster identified in mid-2024. The operation targeted large business-to-business IT service providers in Southern Europe, including organizations delivering data, infrastructure, and cybersecurity services, creating potential downstream supply-chain risk for their customers. The campaign was disrupted in its early stages before confirmed data exfiltration occurred. The intrusion chain relied on SQL injection against internet-facing web and database servers for initial access, followed by deployment of a custom PHP webshell known as PHPsert for foothold establishment and persistence. Post-compromise activity included reconnaissance with native Windows utilities and third-party tools, credential theft from LSASS memory and the Security Account Manager database, and lateral movement primarily through RDP and pass-the-hash techniques. Operators also enabled SSH-based remote access on compromised systems. A notable tradecraft feature was the abuse of trusted Microsoft services and signed binaries for persistence and command-and-control. The operators used Visual Studio Code Remote Tunnels, including a portable Visual Studio Code instance run as a Windows service, to maintain covert remote access while blending malicious traffic with legitimate cloud activity. This reflects a strong emphasis on defense evasion and living-off-trusted-services techniques. The campaign used a custom modified Mimikatz variant referred to as bK2o.exe, assessed as part of a broader custom tooling cluster called mimCN. That tooling overlaps with activity associated with Operation Soft Cell and Operation Tainted Love, suggesting shared development resources or a common tooling supplier within the Chinese APT ecosystem. Additional supporting indicators for a China nexus include simplified Chinese developer artifacts and operator activity aligning with weekday working hours in China.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
22 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.