GoldMelody’s Hidden Chords: Initial Access Broker In-Memory IIS Modules Revealed
ID: c781448e-f1b0-522b-86ab-f6d6ebe502b7
STIX ID: report--c781448e-f1b0-522b-86ab-f6d6ebe502b7
Feed Name: Palo Alto Networks Unit 42
Unit 42 uncovered a campaign (TGR-CRI-0045) exploiting leaked ASP.NET Machine Keys to craft ViewState deserialization payloads that load .NET assemblies into IIS process memory for command execution and post-exploitation activities; the actor, assessed with medium confidence as linked to Gold Melody, targeted organizations across multiple industries, used in-memory reflective loaders and post-exploitation tools (TxPortMap, updf with GodPotato), and left a set of IP and file-hash IoCs along with remediation guidance to rotate Machine Keys and enable telemetry for POST requests.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
