logo

Microsoft says attackers use exposed ASP.NET keys to deploy malware

ID: 826de573-d3d1-51aa-a7e4-25dc3b6fecd8

STIX ID: report--826de573-d3d1-51aa-a7e4-25dc3b6fecd8

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2025-02-06

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Microsoft warns that attackers are using publicly disclosed ASP.NET machineKey values to create malicious ViewState payloads that bypass ViewState integrity protections, enabling remote code execution on IIS web servers; Microsoft has observed active exploitation (including delivery of a post-exploitation framework named Godzilla), identified over 3,000 publicly disclosed keys that could be abused, and recommends securely generating/rotating machine keys, encrypting secrets, upgrading to ASP.NET 4.8 for AMSI, and hardening servers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.