Code Injection Attacks Exploiting Publicly Disclosed ASP.NET Keys (Campaign)
ID: 02388885-fc65-541f-aff4-26603bac958f
STIX ID: report--02388885-fc65-541f-aff4-26603bac958f
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-02-12
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Microsoft Threat Intelligence observed attackers exploiting publicly disclosed ASP.NET machine keys to craft malicious ViewState payloads and achieve remote code execution on IIS servers; in December 2024 this technique was used to deploy the Godzilla post-exploitation framework via a malicious assembly (SHA-256: 19d87910d1a7ad9632161fd9dd6a54c8a059a64fc5f5a41cf5055cd37ec0499d).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
