Wednesday, September 16, 2026
Follow on LinkedIn

Njrat Attacking Users Abusing Microsoft Dev Tunnels for C2 Communications

Security researchers have uncovered a new campaign leveraging the Njrat remote access trojan (RAT) to abuse Microsoft’s developer-oriented Dev Tunnels service for covert command-and-control (C2) communications. 

Historically associated with credential theft and USB-based propagation, the malware now utilizes Microsoft’s infrastructure to evade traditional network defenses by masquerading as legitimate developer activity.

Microsoft Dev Tunnels, designed to expose local services via temporary HTTPS URLs for debugging purposes5, is being weaponized to host Njrat’s C2 servers

SANS Internet Storm Center reported two samples were detected such as:

Their ImpHash (Import Hash) is the same (f34d5f2d4577ed6d9ceec516c1f5a744) despite using distinct dev tunnel URLs:

The malware transmits system metadata to the C2 server via HTTP POST requests, with status updates encoded in variables like OK.HH (host URL) and OK.usb (USB propagation capability). 

Code analysis reveals a JSON-based configuration specifying persistence mechanisms. By routing traffic through Microsoft’s trusted domains (devtunnels.ms), attackers bypass IP/DNS reputation checks and leverage TLS encryption to obscure payloads. 

This mirrors past Njrat campaigns abusing services like Pastebin for C2 tunneling, but with higher sophistication due to Microsoft’s certificate authority trust. 

The malware’s USB propagation module (OK.usb = True) further enables lateral movement in air-gapped environments.

Defenders face visibility gaps, as Dev Tunnels traffic resembles legitimate developer activity. Network telemetry showing prolonged connections to *.devtunnels.ms or processes like devtunnel.exe paired with unsigned binaries may indicate abuse.

Mitigation Recommendations

  • DNS Filtering: Block or alert on requests to devtunnels.ms in unauthorized environments.
  • Endpoint Monitoring: Flag processes combining Microsoft-signed binaries (e.g., devtunnel.exe) with anomalous child processes.
  • Registry Audits: Hunt for Njrat’s persistence key af63c521a8fa69a8f1d113eb79855a75 in HKLM\Software\Microsoft\Windows\CurrentVersion\Run.
  • Network Segmentation: Restrict Dev Tunnels access to developer VLANs only.

Microsoft has not yet commented on the abuse of its service, but the campaign underscores the risks of dual-use developer tools in enterprise networks. 

The threat remains active as of February 28, 2025, with infrastructure linked to historical Njrat campaigns in the Middle East and North Africa.

Security teams are advised to correlate these IOCs with DNS logs and endpoint process trees.

Indicators of Compromise (IOCs)

SHA256 Hashes:

0b0c8fb59db1c32ed9d435abb0f7e2e8c3365325d59b1f3feeba62b7dc0143ee
9ea760274186449a60f2b663f535c4fbbefa74bc050df07614150e8321eccdb7

Domains:

nbw49tk2-25505[.]euw[.]devtunnels[.]ms
nbw49tk2-27602[.]euw[.]devtunnels[.]ms

Collect Threat Intelligence on the Latest Malware and Phishing Attacks with ANY.RUN TI Lookup -> Try for free

Guru Baran
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Cyber Security Guide

Latest Cyber News

Expert Talks