Darktrace reported a spear-phishing campaign targeting South Korean organizations that abuses a legitimate feature in Microsoft Visual Studio Code to establish remote access without deploying traditional command-and-control infrastructure. The lures used government-themed content, delivering files described as JSE scripts disguised as Hangul Word Processor (HWPX) documents; when opened, they installed VS Code and enabled VS Code Tunnels, allowing attackers to remotely control compromised hosts over trusted Microsoft infrastructure. Darktrace assessed the activity as heavily living-off-the-land and noted it as an apparent first for DPRK-linked actors using this specific tunneling technique.
Other items in the set describe separate, unrelated activity and should not be conflated with the VS Code tunneling campaign. KnowBe4 detailed a dual-wave phishing operation that steals credentials and then weaponizes legitimate RMM tools for persistence; CybersecurityNews described a multi-stage Windows infection chain that uses LNK/PowerShell, GitHub-hosted loaders, Telegram Bot API communications, and repurposes the Defendnot tool to disable Microsoft Defender before dropping additional payloads; and The Hacker News “ThreatsDay” bulletin and Black Hills InfoSec’s “common threats” article are broad roundups/generic content rather than reporting the same South Korea VS Code incident. Darktrace’s separate blog post also discusses rapid exploitation of CVE-2025-55812 (React2Shell) against exposed Next.js/React Server Components, which is a different topic from the DPRK VS Code Tunnels intrusion activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Alongside its reporting on the South Korea-focused campaign, Darktrace released indicators of compromise and mapped the observed activity to MITRE ATT&CK techniques. The publication highlighted the campaign’s living-off-the-land tradecraft and the difficulty of detecting abuse of common developer tools.
Darktrace reported a spear-phishing campaign targeting South Korean victims in which government-themed lures delivered JSE files disguised as HWPX documents. The files installed Visual Studio Code and abused its built-in tunneling feature to give attackers remote access over trusted Microsoft infrastructure.
During the broader React2Shell exploitation wave, Darktrace observed likely North Korea–affiliated actors targeting financial-sector organizations across multiple countries. The activity included DPRK-linked tooling such as a Beavertail variant and a previously undocumented Linux implant called EtherRAT.
In a case study, attackers achieved remote code execution on an internet-facing Azure VM running Next.js shortly after it was exposed. They then staged a Go-based RAT and followed with cryptomining payloads including XMRig.
Darktrace observed its honeypot being exploited within two minutes of deployment, showing that attackers were already actively scanning for and exploiting vulnerable internet-facing systems. The activity quickly progressed from reconnaissance to scripted payload delivery, outbound beaconing, and cryptomining.
A public proof-of-concept for React2Shell appeared within 30 hours of the patch and disclosure, sharply reducing defenders’ response window. This accelerated the move from disclosure to in-the-wild exploitation.
CVE-2025-55812, dubbed “React2Shell,” was discovered and patched for affected React Server Components and exposed Next.js servers. Darktrace says this occurred on December 3, 2025.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.