INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability

| 2026-05-25 14:00 CRITICAL HIGH
Executive Summary AI-generated
The threat actor has been identified as a sophisticated and highly adaptable adversary, utilizing various tactics including exploitation of known vulnerabilities such as ViewState Deserialization Vulnerability in ASP.NET applications. The use of KnowledgeDeliver instances to spread malware is also notable, highlighting the importance of robust security measures against these types of threats. Furthermore, the deployment of a .NET-based in-memory web shell called BLUEBEAM further underscores the threat actor's ability to maintain persistence and control within compromised systems.
Technical Mitigations AI-generated
• Monitor Application Event Logs for specific event IDs (1316) and failed integrity checks, as well as successful execution of ViewState deserialization attempts. • Implement Suspicious Process Activity Monitoring to detect unusual child processes spawned by w3wp.exe, including cmd.exe /c commands that may indicate a BLUEBEAM web shell deployment. • Perform File Integrity Monitoring on .js, .aspx, and .config files within the web root for unauthorized changes or additions of remote script loaders or unusual logic.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Cobalt StrikeCobalt Strike
Target & Sectors
NORTH_AMERICA NORTH_AMERICA
Incident Timeline
‎2026/05/25
Threat actors exploited a ViewState Deserialization Vulnerability in KnowledgeDeliver to infect workstations with Cobalt Strike BEACON backdoors.
infrastructure Windows
organisation U
organisation Monitor the Windows Application
organisation KHTML
organisation Win64
infrastructure 11.01
infrastructure 5.0
infrastructure 10.0
infrastructure 537.36
infrastructure 121.0.0
infrastructure 9.0
infrastructure 6.1
infrastructure 10.0.648
organisation MSIE
organisation KnowledgeDeliver
organisation ViewState Deserialization Vulnerability
organisation ViewState
organisation Vulnerability affecting
organisation Mandiant
organisation ASP.NET
organisation Microsoft
organisation Post-Exploitation Activity Once
organisation BLUEBEAM
organisation File Tampering
organisation Failed Attempt
organisation File Integrity Monitoring Monitor
organisation ViewState Deserialization Zero-Day
organisation LMS
organisation IP
organisation Outlook and Implications The
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎11.01
Software Version
Metrics
infrastructure
‎5.0
Software Version
Metrics
infrastructure
‎10.0
Software Version
Metrics
infrastructure
‎537.36
Software Version
Metrics
infrastructure
‎121.0.0
Software Version
Metrics
infrastructure
‎9.0
Software Version
Metrics
infrastructure
‎6.1
Software Version
Metrics
infrastructure
‎10.0.648
Software Version