Microsoft signed and hosted Reverse Shell
MS is offering a signed binary (code.exe), which will establish a Command&Control channel via an official Microsoft domain https://vscode.dev. The C2 communication itself is going to https://global.rel.tunnels.api.visualstudio.com over WebSockets. An attacker only needs an Github account. Let’s Go (VS) Code - Red Team style or the Microsoft signed and hosted Reverse Shell