Attackers Abuse Velociraptor Forensic Tool to Deploy Visual Studio Code for C2 Tunneling
Researchers studying cybersecurity have drawn attention to a cyberattack in which unidentified threat actors used Velociraptor, an open-source endpoint monitoring and digital forensic tool, to demonstrate the persistent misuse of trustworthy software for malevolent ends.
According to a report released this week by the Sophos Counter Threat Unit Research Team, the threat actor in this instance downloaded and ran Visual Studio Code using the tool with the probable goal of establishing a tunnel to an attacker-controlled command-and-control (C2) server.
Although threat actors are known to use legitimate remote monitoring and management (RMM) tools or living-off-the-land (LotL) tactics in their attacks, Velociraptor's use indicates a tactical evolution in which incident response programs...

