INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability

| 2026-05-25 14:00 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The threat actor has been identified as a sophisticated and highly adaptable adversary, utilizing various tactics including exploitation of known vulnerabilities such as ViewState Deserialization Vulnerability in ASP.NET applications. The use of KnowledgeDeliver instances to spread malware is also notable, highlighting the importance of robust security measures against these types of threats. Furthermore, the deployment of a .NET-based in-memory web shell called BLUEBEAM further underscores the threat actor's ability to maintain persistence and control within compromised systems.
Technical Mitigations AI-generated
• Monitor Application Event Logs for specific event IDs (1316) and failed integrity checks, as well as successful execution of ViewState deserialization attempts. • Implement Suspicious Process Activity Monitoring to detect unusual child processes spawned by <a href="/auth/login?next=/detail/p7OhXp4BHUyMcQl6ph5c" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN &bull; LOGIN REQUIRED]</span></a>, including <a href="/auth/login?next=/detail/p7OhXp4BHUyMcQl6ph5c" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN &bull; LOGIN REQUIRED]</span></a> /c commands that may indicate a BLUEBEAM web shell deployment. • Perform File Integrity Monitoring on .js, .aspx, and .config files within the web root for unauthorized changes or additions of remote script loaders or unusual logic.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

w3•••••.exe
po•••••.exe
cm•••••.exe
121.0.•••.•••
1.9.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Cobalt StrikeCobalt Strike
Target & Sectors
NORTH_AMERICA NORTH_AMERICA
Incident Timeline
‎2026/05/25
Threat actors exploited a ViewState Deserialization Vulnerability in KnowledgeDeliver to infect workstations with Cobalt Strike BEACON backdoors.
infrastructure Windows
organisation U
organisation Monitor the Windows Application
organisation KHTML
organisation Win64
infrastructure 11.01
infrastructure 5.0
infrastructure 10.0
infrastructure 537.36
infrastructure 121.0.0
infrastructure 9.0
infrastructure 6.1
infrastructure 10.0.648
organisation MSIE
organisation KnowledgeDeliver
organisation ViewState Deserialization Vulnerability
organisation ViewState
organisation Vulnerability affecting
organisation Mandiant
organisation ASP.NET
organisation Microsoft
organisation Post-Exploitation Activity Once
organisation BLUEBEAM
organisation File Tampering
organisation Failed Attempt
organisation File Integrity Monitoring Monitor
organisation ViewState Deserialization Zero-Day
organisation LMS
organisation IP
organisation Outlook and Implications The
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎11.01
Software Version
Metrics
infrastructure
‎5.0
Software Version
Metrics
infrastructure
‎10.0
Software Version
Metrics
infrastructure
‎537.36
Software Version
Metrics
infrastructure
‎121.0.0
Software Version
Metrics
infrastructure
‎9.0
Software Version
Metrics
infrastructure
‎6.1
Software Version
Metrics
infrastructure
‎10.0.648
Software Version