In-Memory IIS Attacks via View State Deserialization (Campaign)
ID: 6578c81f-ef84-51db-9e17-6dbed36f87f7
STIX ID: report--6578c81f-ef84-51db-9e17-6dbed36f87f7
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-07-08
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Unit42 reports a campaign by an actor tied to Gold Melody (UNC961) that used compromised ASP.NET Machine Keys to craft malicious ViewState payloads, enabling in-memory execution inside IIS (w3wp.exe) without writing files to disk. The intrusions—observed across at least a dozen organizations in critical sectors in the U.S. and Europe during late 2024 into early 2025—included command execution, file upload modules, privilege escalation via GodPotato, host/network reconnaissance, and use of disguised binaries and utilities; the technique required re-upload and re-execution per command, producing a low forensic footprint.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
