/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Microsoft warns that attackers are using static ASP.NET machine keys found online to inject malware into ViewState, which controls web form state during reloads

https://www.microsoft.com/en-us/ security/blog/2025/02/06/code-injection - attacks-using-publicly-disclosed-asp- net-machine-keys/ @youranonriots : Microsoft warns that attackers are deploying malware in ViewState code injection attacks using static ASP.  NET machine keys found online. #codeinjection #CyberAlerts www.bleepingcomputer.com/news/ securit... Mastodon: @0xabad1dea@infosec.exchange : Do all the junior footgun engineers of the world a favor and never put works-as-is encryption keys in your documentation or example configuration files. https://www.microsoft.com/... @screaminggoat@infosec.exchange : Microsoft: Code injection attacks using publicly disclosed ASP.NET machine keys  —  In December 2024, Microsoft Threat Intelligence observed limited activity by an unattributed threat actor using a publicly available, static ASP.NET machine key to inject malicious code and deliver the Godzilla post-exploitation framework. …

BleepingComputer Sergiu Gatlan

Context & Ripple Effects

Microsoft Threat Intelligence observed limited activity in December 2024 in which an unattributed actor used a publicly available machine key to deliver the Godzilla post-exploitation framework. The warning turns a configuration-management error into a concrete application-compromise path.

The incident sits alongside Microsoft's recurring disclosure of actively exploited enterprise software weaknesses, including a critical Windows RCE reported as active in the wild. Here, the exposure is not a newly disclosed product flaw but reuse of static secrets that were already public.

First-order effects

  • Organizations running ASP.NET applications with exposed or copied static machine keys face a direct risk that attackers can forge or alter ViewState data and execute injected malicious code.
  • Microsoft's finding gives defenders a specific remediation target: identify affected static keys, replace them, and investigate applications for ViewState-based compromise, including delivery of the Godzilla framework.

Second-order effects

  • Application owners and security teams will need to treat sample and legacy configuration material as credential exposure, increasing pressure to inventory secrets embedded in code, documentation, and deployments.
  • The technique shifts attention from perimeter exploitation to integrity controls inside web applications: monitoring and incident response must account for malicious requests that appear valid because they are signed with a known key.

Third-order effects

  • If reuse of published application secrets persists, secure defaults and secret-rotation practices may become as consequential to web-application resilience as patching conventional vulnerabilities.
  • The broader security boundary is moving toward configuration provenance: organizations will need to distinguish vendor or community examples from production-safe cryptographic material before deploying them at scale.

The trend: Publicly available configuration secrets are increasingly becoming a practical attack path for turning trusted application mechanisms into code-execution channels.

Discussion

  • @tmjintel @tmjintel on bluesky
    Code injection attacks using publicly disclosed ASP.NET machine keys  —  https://www.microsoft.com/en-us/ security/blog/2025/02/06/code-injection - attacks-using-publicly-disclosed-asp- net-machine-keys/
  • @youranonriots @youranonriots on bluesky
    Microsoft warns that attackers are deploying malware in ViewState code injection attacks using static ASP.  NET machine keys found online. #codeinjection #CyberAlerts www.bleepingcomputer.com/news/ securit...