logo

Code injection attacks using publicly disclosed ASP.NET machine keys

ID: f36de57e-6ab5-5cc8-915b-97dee681e0f9

STIX ID: report--f36de57e-6ab5-5cc8-915b-97dee681e0f9

Feed Name: Microsoft Security

Threat Score
70/100

Date Published: 2025-02-06

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence

...
...

Microsoft Threat Intelligence observed limited December 2024 activity where an attacker exploited publicly disclosed ASP.NET machine keys to perform ViewState code injection and load the Godzilla post-exploitation framework; the report explains the attack chain, lists indicators (including a Godzilla DLL SHA-256), and provides detection, hunting, and remediation guidance such as rotating/removing machineKey values and auditing configuration files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.