logo

Code Injection Attacks Exploiting Publicly Disclosed ASP.NET Keys (Campaign)

ID: 02388885-fc65-541f-aff4-26603bac958f

STIX ID: report--02388885-fc65-541f-aff4-26603bac958f

Feed Name: Wiz Cloud Threat Landscape

Threat Score
75/100

Date Published: 2025-02-12

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Microsoft Threat Intelligence observed attackers exploiting publicly disclosed ASP.NET machine keys to craft malicious ViewState payloads and achieve remote code execution on IIS servers; in December 2024 this technique was used to deploy the Godzilla post-exploitation framework via a malicious assembly (SHA-256: 19d87910d1a7ad9632161fd9dd6a54c8a059a64fc5f5a41cf5055cd37ec0499d).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.