Microsoft warned that attackers are actively using publicly disclosed ASP.NET machineKey values to achieve remote code execution on vulnerable IIS-hosted ASP.NET applications. The attacks abuse exposed static validationKey and decryptionKey values to generate malicious ViewState payloads with valid message authentication codes, allowing the ASP.NET runtime to accept and execute attacker-controlled data. Microsoft said the activity has been observed since at least December 2024 and linked some intrusions to deployment of the Godzilla post-exploitation framework.
The company identified more than 3,000 leaked keys and released their hashes in a CSV file so organizations can check whether their environments are exposed. Guidance from Microsoft and CSIRT.SK urges defenders to replace any public or default keys, protect sensitive web.config elements through encryption, upgrade ASP.NET to at least version 4.8, and further harden Windows and IIS servers to reduce the risk of malware deployment and follow-on compromise.

See which actors are running it and whether you're in range.
2 events from the most recent confirmed update back to the earliest known activity.
On February 6, 2025, Microsoft warned that attackers were using exposed ASP.NET machine keys for code injection attacks and said it had identified more than 3,000 leaked keys. Microsoft also published hashes of the discovered keys in a CSV file to help organizations identify exposure.
Microsoft reported that threat actors had been actively abusing publicly disclosed ASP.NET machine keys since at least December 2024 to achieve remote code execution against vulnerable ASP.NET applications. Observed post-compromise activity included deployment of malware and use of the Godzilla framework.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.