PassiveNeuron Campaign: Espionage Campaign Targeting Windows Server Environments (Campaign)
ID: 9b2da55d-6cba-5b76-b4e9-bf423a401857
STIX ID: report--9b2da55d-6cba-5b76-b4e9-bf423a401857
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-10-21
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
IIS-targeting campaign abuses exposed/reused ASP.NET machineKey (ValidationKey/DecryptionKey) to trigger __VIEWSTATE deserialization and remotely execute commands, after which operators (REF3927) deploy Godzilla-family webshells and the TOLLBOOTH backdoor (native/.NET) placed in inetsrv paths, retrieve per-victim config from c.cseo99.com, cache artifacts in Windows Temp, and use a Wingtb-derived kernel rootkit plus tools like Mimikatz to steal credentials, hide activity, clear logs, and persist; hundreds of infections and recurring reinfections were observed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
