Code injection attacks using publicly disclosed ASP.NET machine keys
ID: f36de57e-6ab5-5cc8-915b-97dee681e0f9
STIX ID: report--f36de57e-6ab5-5cc8-915b-97dee681e0f9
Feed Name: Microsoft Security
Threat Score
Microsoft Threat Intelligence observed limited December 2024 activity where an attacker exploited publicly disclosed ASP.NET machine keys to perform ViewState code injection and load the Godzilla post-exploitation framework; the report explains the attack chain, lists indicators (including a Godzilla DLL SHA-256), and provides detection, hunting, and remediation guidance such as rotating/removing machineKey values and auditing configuration files.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
