logo

Hackers Abuse KnowledgeDeliver LMS Flaw to Install BLUEBEAM Web Shell

ID: 6e8e51aa-6656-5308-a11e-4908631b5388

STIX ID: report--6e8e51aa-6656-5308-a11e-4908631b5388

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-05-26

Date Updated: 2026-05-26

Author: Divya

...
...

Mandiant/Google Threat Intelligence observed active exploitation of CVE-2026-5426 in KnowledgeDeliver LMS instances using a shared, hardcoded ASP.NET machineKey to craft malicious ViewState payloads, enabling unauthenticated RCE; intruders deployed the BLUEBEAM (Godzilla) .NET in-memory web shell in the IIS worker process, modified permissions and web files, and used a fake plugin to deliver Cobalt Strike payloads. The report provides an IOC (SHA-256 for LoadLibrary.dll), recommends rotating machine keys, monitoring Event ID 1316 and w3wp.exe activity, and restricting access and file integrity monitoring to mitigate risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.