Select your language

Cyberattacks exploit vulnerabilities in ASP.NET and expose critical infrastructure

An advanced cyber operation has recently been identified, led by a group of Initial Access Brokers (IABs) that exploit leaked machine keys in applications developed with ASP.NET.

In this situation, the detected set is Prophet Spider, a group that puts vulnerable web servers at risk to allow access to third parties, which then deploy malware or ransomware. Its goals span European and American entities in areas such as finance, manufacturing, trade and transportation.

The collective employs a method called ASP.NET view state deserialization, through which it executes malicious code directly into the server's memory. This prevents conventional forensic fingerprints and makes it easier for each malicious command to be processed individually.

Once executed, these payloads are handled within the framework of the IIS (Internet Information Services) server, allowing intruders to execute commands, move files, and maintain access constantly.  In addition, the repeated use of the C:\Windows\Temp\111t directory and the updf binary was noted, which uses the GodPotato attack to escalate privileges and gain SYSTEM-level access.

- Publicidad -

"The main objective continues to be to establish and maintain initial accesses, which can later be marketed with other criminal actors within the cybercrime ecosystem," explains Víctor Ruiz, founder of SILIKN and author of the analysis.

The research notes that one of the biggest detection challenges lies in the fact that the POST requests used in these attacks are rarely logged by traditional systems. In addition, the use of techniques such as reflexive loading of .NET assemblies allows Prophet Spider to evade standard controls on endpoints.

In Mexico, SILIKN's research unit identified that nearly 400 government agencies have similar vulnerable configurations, including the Federal Electricity Commission (CFE) and the National Water Commission (Conagua).

"The CFE has historically been a frequent target of cyberattacks," the report states. In 2015, approximately 70% of the attacks directed at the federal government focused on CFE and Pemex. In 2019, more than 4,200 events were recorded in a five-month period. During 2020, the Superior Audit of the Federation warned about the absence of updates and penetration tests. In response, the CFE allocated more than 400 million pesos in 2025 to update its systems and strengthen surveillance, especially after global events such as blackouts attributed to groups such as Guacamaya.

For its part, Conagua was affected in April 2023 by the BlackByte ransomware, which paralyzed its systems, including the National Water Information System and the servers of the National Meteorological Service.

Experts recommend that organizations review their ASP.NET implementations to detect exposed machine keys and verify that view state MAC is enabled. They also suggest conditionally logging POST requests, monitoring for Windows Event 1316, and using advanced endpoint detection solutions to identify .NET reflective load.

"Advanced monitoring and permanent updating of technological infrastructures are essential to contain this new wave of threats," concludes Ruiz.

Andrea Ochoa Restrepo
Andrea Ochoa RestrepoEmail: [email protected]
Editora
Comunicadora Social- Periodista. MSC en Economía Aplicada con énfasis en Políticas Públicas. Diplomada en Emergencia Climática. Con más de 12 años en medios.

No comments

• If you're already registered, please log in first. Your email will not be published.

Leave your comment

In reply to Some User
Security becomes a technological platform

Security becomes a technological platform

Mexico. Security is moving from a set of standalone systems to an integrated technology platform that combines artificial intelligence, video analytics, sensors, access control, and data platforms....

Security industry in Mexico and Latin America continues its expansion and professionalization

Security industry in Mexico and Latin America continues its expansion and professionalization

International. The security industry in Mexico and Latin America maintains a growth trend driven by digital transformation, the increase in physical and cyber risks, as well as the need to protect...

Veeam Introduces Agent Commander to Address AI Agent Risks in Enterprise Environments

Veeam Introduces Agent Commander to Address AI Agent Risks in Enterprise Environments

United States. Veeam Software today announced the launch of Agent Commander, a solution aimed at helping organizations detect risks associated with artificial intelligence, protect AI-based systems...

Key and asset management, the key to optimizing operations in logistics, distribution and construction companies

Key and asset management, the key to optimizing operations in logistics, distribution and construction companies

In industries where every minute counts, efficient asset and resource management has become a strategic factor to ensure operational continuity, safety, and productivity. By: Héctor Meléndez,...

Genesis Security Reduces False Alarms by 62% Through Milestone Integration and Actuate AI Analytics

Genesis Security Reduces False Alarms by 62% Through Milestone Integration and Actuate AI Analytics

Puerto Rico. A centralized monitoring operation developed by Genesis Security was able to significantly reduce the volume of false alarms in its security systems, thanks to the integration of...

Case study: Solar cameras and thermal intelligence optimize the safety of aquaculture farms

Case study: Solar cameras and thermal intelligence optimize the safety of aquaculture farms

Türkiye. An open-ocean fish farming farm in Turkey implemented a smart surveillance system based on Dahua solar cameras, thermal monitoring, and wireless data transmission to improve safety and...

 The Hidden Security Gap in Data Centers

The Hidden Security Gap in Data Centers

Imagine the journey of an authorized technician inside a data center. When he arrives, he presents his credential and enters the premises, and before entering the server corridor he needs a key to...

Digital fraud increased at Christmas

Digital fraud increased at Christmas

Colombia. During the holiday season, as e-commerce and digital transactions intensified, online fraud attempts also increased. Fake promotions, impersonation of businesses and messages that...

Milestone XPerience Days arrived in Mexico City with innovations in intelligent video management

Milestone XPerience Days arrived in Mexico City with innovations in intelligent video management

Mexico. Milestone Systems, a leading provider of open platform video management software (VMS), hosted the Milestone XPerience Days Mexico 2025 event, a gathering that brought together industry...

Hikvision Mexico launches the third edition of

Hikvision Mexico launches the third edition of "Hikvision Women"

Mexico. Hikvision Mexico announced the launch of the third edition of its "Hikvision Women" program, an initiative aimed at strengthening the participation and professional development of women in...

Suscribase Gratis
Remember Me
SUBSCRIBE TO OUR ENGLISH NEWSLETTER
DO YOU NEED A SERVICE OR PRODUCT QUOTE?
LATEST INTERVIEWS
SITE SPONSORS










LATEST NEWSLETTER
Latest Newsletter