logo

Spec-tac-ula Deserialization: Deploying Specula with .NET

ID: 238915e9-3630-5792-9c6c-bca6b8037b48

STIX ID: report--238915e9-3630-5792-9c6c-bca6b8037b48

Feed Name: TrustedSec blog

Threat Score
65/100

Date Published: 2025-03-27

Date Updated: 2026-05-01

...
...

This post demonstrates a proof-of-concept exploit chain that abuses insecure .NET BinaryFormatter deserialization to achieve remote code execution and in-memory assembly loading via ysoserial.net gadget chains (XamlAssemblyLoadFromFile). The author modifies ysoserial to accept DLLs, builds a payload that loads a custom assembly to modify registry keys, and shows how these modifications can deploy Specula (an Outlook webview backdoor) for persistence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.