WEEPSTEEL is a reconnaissance-focused backdoor used in espionage-oriented intrusions against vulnerable ASP.NET-based web applications, most notably internet-exposed Sitecore servers compromised through ViewState deserialization attacks involving unsafe machineKey values. It has been observed in campaigns exploiting CVE-2025-53690, where attackers achieve remote code execution on Sitecore systems and deploy WEEPSTEEL early in the intrusion to survey the environment and support follow-on operations.
The malware has been associated with a .NET assembly referred to as Information.dll. Its core function is internal reconnaissance: it enumerates host details, disk information, network adapters, running processes, and related system data, then returns the collected results in a form intended to blend with normal ASP.NET ViewState traffic. Reporting also characterizes WEEPSTEEL as enabling persistent access and supporting long-term espionage objectives, including staging of additional tooling for remote access, lateral movement, and eventual data theft.
WEEPSTEEL has been linked to activity attributed to UAT-8837, a China-linked threat actor assessed to target organizations for initial access and espionage. In observed Sitecore compromises, WEEPSTEEL deployment was followed by broader post-exploitation actions including creation of unauthorized administrative accounts, installation of remote administration and tunneling tools such as DWAgent and Earthworm, credential-access activity, collection of configuration data, and exfiltration of sensitive information. Victimology reported around these campaigns includes critical infrastructure and other enterprise environments in North America, with Sitecore servers serving as the initial foothold.
The malware is best understood as a lightweight reconnaissance backdoor used to establish situational awareness on compromised Windows servers and facilitate subsequent operator-driven intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2025-53690 is a ViewState deserialization vulnerability that affects any version of Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud deployed in the manner above. Successful exploitation of the vulnerability might lead to remote code execution and non-authorised access to information. | WEEPSTEEL (Information.dll)
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Mandiant researchers reported CVE-2025-53690 as an actively exploited zero-day in early September 2025, in an attack where they observed the deployment of a reconnaissance backdoor named 'WeepSteel'.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
WeepSteel is described as a spying tool installed via ViewState deserialization attacks to reveal the ASP.NET machine key on Sitecore servers.
Reconnaissance-focused backdoor used for long-term espionage and data exfiltration. It performs system and network discovery, establishes persistence via custom DLLs (e.g., dropped as Information.dll), and supports follow-on activity including staging remote administration (DWAgent) and tunneling (Earthworm).
A reconnaissance backdoor deployed after exploitation of a Sitecore ViewState deserialization zero-day (CVE-2025-53690) to enable post-compromise access and reconnaissance.
WEEPSTEEL is a malware tool used for internal reconnaissance after initial compromise, aiding in lateral movement and further exploitation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.