216.73.217.22

Code injection attacks using publicly disclosed ASP.NET machine keys

· Published 06/02/2025 22:31 · Modified 06/02/2025 23:20

Export JSON

Essential information

Published
06/02/2025 22:31
Modified
06/02/2025 23:20
Tags
2025-02-06 asp.net code injection godzilla iis machine keys post-exploitation viewstate web servers
Related entities
4 techniques (mitre), 1 malware

Description

An unattributed threat actor has been observed exploiting publicly disclosed to perform attacks, delivering the framework. Over 3,000 publicly disclosed keys have been identified as potentially vulnerable to this attack method. The attack chain involves crafting malicious data using stolen keys, sending it to the target website via POST request, and executing malicious code on the web server. Microsoft recommends against using publicly available keys, regular key rotation, and provides detection and mitigation strategies. Affected organizations should investigate for possible backdoors or persistence methods established by threat actors.

External references