During Operation Digital Eye, threat actors targeted memory from the LSASS process to extract credentials.2
campaign
Operation Digital Eye C0061
- First seen
- June 2024
- Last seen
- July 2024
- Created
- 19 April 2026
- Last modified
- 31 July 2026
Operation Digital Eye was conducted in June and July of 2024 by suspected People's Republic of China (PRC)-nexus threat actors targeting business-to-business IT service providers in Southern Europe. Operation Digital Eye activity included the use of Visual Studio Code tunnels for command and control (C2) and custom lateral movement capabilities. Overlaps in tooling between Digital Eye and previous China-nexus campaigns, Operation Soft Cell and Operation Tainted Love, indicate the potential use of shared vendors or digital quartermasters.[1]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference C0061
During Operation Digital Eye, threat actors used reg save to retrieve credentials from the Security Account Manager (SAM) database.3
During Operation Digital Eye, threat actors used Ping for reconnaissance.4
During Operation Digital Eye, threat actors moved laterally using RDP.5
During Operation Digital Eye, threat actors used GetUserInfo to identify current user information.6
During Operation Digital Eye, threat actors attempted to make filenames appear legitimate by tailoring them to the victim organization.7
Standing C0061
Reach is how much of ATT&CK this campaign touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 56 ATT&CK campaigns only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
64th percentile · 64% of 56 ATT&CK campaigns have this many Enterprise techniques or fewer.
77th percentile · 77% of 56 ATT&CK campaigns have this many tactics spanned or fewer.
71st percentile · 71% of 56 ATT&CK campaigns have this many tools and malware or fewer.
55% of the population shares a single value across only 3 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
89th percentile · 89% of 56 ATT&CK campaigns have this many detection rules per technique or fewer.
Detection coverage C0061
820 distinct rules cover the 22 techniques recorded for this campaign. The 905 technique-to-rule mappings resolve to 820 distinct rules, because one rule can cover several techniques. 537 Sigma · 283 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org