Network Security, Threat Intelligence

Exposed ASP.NET machine keys leveraged for network infiltration

Glowing digital key on a dark circuit board symbolizing cybersecurity and data encryption. Cybersecurity awareness, data protection, digital security, IT, information safety, encryption concept.

Attacks leveraging exposed ASP.NET machine keys have been deployed by initial access broker Gold Melody, also known as UNC961 and Prophet Spider, to facilitate network compromise as part of the TGR-CRI-0045 campaign, with such access later sold to other illicit actors, The Hacker News reports.

Gold Melody used the ASP.NET machine keys to enable direct in-memory execution of malicious payloads while ensuring covert operations, an analysis from Palo Alto Networks Unit 42 researchers showed. Intensified intrusions from late January to March resulted in the delivery of open-source port scanners and other post-exploitation tools. Unit 42 researchers noted that attacks from Internet Information Services servers allowed in-memory execution of a .NET assembly and the download of other tools for reconnaissance while circumventing ViewState defenses. "The group's opportunistic targeting and ongoing tool development highlight the need for organizations to prioritize identifying and remediating compromised Machine Keys," said researchers.

An In-Depth Guide to Network Security

Get essential knowledge and practical strategies to fortify your network security.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds