{
  "Event": {
    "analysis": "1",
    "date": "2026-05-26",
    "extends_uuid": "",
    "info": "[Threat Intel] Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability",
    "protected": false,
    "publish_timestamp": "1780293082",
    "published": true,
    "threat_level_id": "2",
    "timestamp": "1780293082",
    "uuid": "7d11ee85-edb4-4c0d-8857-1c31a3bbf632",
    "Orgc": {
      "name": "Rectifyq",
      "uuid": "cd9bd516-61fa-476b-980f-2f8de03992d4"
    },
    "Tag": [
      {
        "colour": "#6e57da",
        "local": false,
        "name": "misp-galaxy:producer=\"Mandiant\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"none-from-src\"",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-OTX\"",
        "relationship_type": ""
      },
      {
        "colour": "#7da4ad",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Match Legitimate Resource Name or Location - T1036.005\"",
        "relationship_type": ""
      },
      {
        "colour": "#47d9d3",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#c202a1",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Spearphishing Link - T1566.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#1a4554",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Windows Permissions - T1222.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#7d7034",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"",
        "relationship_type": ""
      },
      {
        "colour": "#f5a258",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Native API - T1106\"",
        "relationship_type": ""
      },
      {
        "colour": "#9feaf0",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"",
        "relationship_type": ""
      },
      {
        "colour": "#edf46c",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Timestomp - T1070.006\"",
        "relationship_type": ""
      },
      {
        "colour": "#fe1ef0",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Web Shell - T1505.003\"",
        "relationship_type": ""
      },
      {
        "colour": "#36a9d8",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Account Discovery - T1087\"",
        "relationship_type": ""
      },
      {
        "colour": "#0c0051",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"",
        "relationship_type": ""
      },
      {
        "colour": "#62f4c1",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Process Discovery - T1057\"",
        "relationship_type": ""
      },
      {
        "colour": "#755c09",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#b76d96",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#f798db",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Indicator Removal from Tools - T1027.005\"",
        "relationship_type": ""
      },
      {
        "colour": "#6d779a",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"",
        "relationship_type": ""
      },
      {
        "colour": "#e08bb2",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"",
        "relationship_type": ""
      },
      {
        "colour": "#356c41",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Encrypted Channel - T1573\"",
        "relationship_type": ""
      },
      {
        "colour": "#02475d",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Windows Command Shell - T1059.003\"",
        "relationship_type": ""
      },
      {
        "colour": "#92e858",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#5887a6",
        "local": false,
        "name": "misp-galaxy:target-information=\"Japan\"",
        "relationship_type": ""
      },
      {
        "colour": "#49a260",
        "local": false,
        "name": "rectifyq:category=\"threat\"",
        "relationship_type": ""
      },
      {
        "colour": "#120044",
        "local": false,
        "name": "rectifyq:sub-category=\"intrusion-analysis\"",
        "relationship_type": ""
      },
      {
        "colour": "#d92121",
        "local": false,
        "name": "rectifyq:target=\"targeted\"",
        "relationship_type": ""
      },
      {
        "colour": "#31373d",
        "local": false,
        "name": "rectifyq:MY-relevancy=\"not-relevant\"",
        "relationship_type": ""
      },
      {
        "colour": "#220082",
        "local": false,
        "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
        "relationship_type": ""
      },
      {
        "colour": "#230087",
        "local": false,
        "name": "rectifyq:samples-found-in=\"Tria.ge\"",
        "relationship_type": ""
      },
      {
        "colour": "#3800d9",
        "local": false,
        "name": "rectifyq:action-taken=\"VT-comment\"",
        "relationship_type": ""
      },
      {
        "colour": "#3d00e9",
        "local": false,
        "name": "rectifyq:action-taken=\"telegram\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779706805",
        "to_ids": false,
        "type": "link",
        "uuid": "50af9064-728c-4e61-b7f5-5897666a8182",
        "value": "https://cloud.google.com/blog/topics/threat-intelligence/knowledgedeliver-viewstate-deserialization-vulnerability"
      },
      {
        "category": "Other",
        "comment": "Description",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779706805",
        "to_ids": false,
        "type": "text",
        "uuid": "bcd0cbfd-6d82-423e-be47-81fe55d18a8f",
        "value": "In late 2025, an unknown threat actor exploited a critical zero-day vulnerability in KnowledgeDeliver, a Learning Management System widely used in Japan. The vulnerability, tracked as CVE-2026-5426, allowed unauthenticated remote code execution through ViewState deserialization attacks. The issue stemmed from identical hardcoded ASP.NET machine keys distributed across multiple customer deployments in the vendor's configuration files. Attackers obtained these keys from one deployment and used them to compromise other internet-facing instances. Following initial access, threat actors deployed the BLUEBEAM in-memory web shell, modified JavaScript files to display fake security alerts, and tricked users into installing malicious software that delivered Cobalt Strike BEACON backdoors. The attack demonstrates the severe risks of shared secrets in deployment templates and highlights the importance of unique cryptographic keys per installation."
      },
      {
        "category": "Other",
        "comment": "Summary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779706805",
        "to_ids": false,
        "type": "text",
        "uuid": "3b6fbf6f-1d46-4240-b84b-b8ea67beb595",
        "value": "Name: Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability\nAuthor: AlienVault\nAdversary: \nTags: [\"zero-day exploitation\", \"bluebeam\", \"viewstate deserialization\", \"cobalt strike\", \"bluebeam web shell\"]\nTgtd countries: [\"Japan\"]\nMlwr families: [\"BLUEBEAM\", \"Godzilla\", \"Cobalt Strike - S0154\"]\nAttack_ids: [\"T1036.005\", \"T1204.002\", \"T1566.002\", \"T1222.001\", \"T1082\", \"T1106\", \"T1190\", \"T1070.006\", \"T1505.003\", \"T1087\", \"T1083\", \"T1057\", \"T1059.001\", \"T1547.001\", \"T1027.005\", \"T1068\", \"T1027\", \"T1573\", \"T1059.003\", \"T1071.001\"]\nIndustries: [\"Education\"]"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779706805",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "dfccfe94-0625-4010-b16b-9e12a862e69a",
        "value": "CVE-2026-5426"
      }
    ],
    "Object": [
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1780288289",
        "uuid": "0c813869-e157-4c72-afea-d6531f0c86e5",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "BLUEBEAM",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1780288289",
            "to_ids": true,
            "type": "md5",
            "uuid": "f2adfdf4-a571-4ac9-bf69-91cd739a65e6",
            "value": "1e7793ad49725c8562218bffd1de8759",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "BLUEBEAM",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1780287680",
            "to_ids": true,
            "type": "sha1",
            "uuid": "07b06ca8-e755-40b9-ac0e-3f48721371b6",
            "value": "39eb147d7b7fec6981a213d5607e42cced1b32a3",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "BLUEBEAM",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1780287680",
            "to_ids": true,
            "type": "sha256",
            "uuid": "866421da-fa8f-4fae-9ab9-874bd92f7e6d",
            "value": "7c1f99dca8e5a7897892f9d224a6495023a2cfd2671697d229d355978c415ed2",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1780284688",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "25868cbc-e998-4b9e-85c0-df7e22085a6a",
            "value": "192:3wA0lD2X60EnANAbQftKE/tlkhIj5x8sajNnLzvkWmdrNnVJ:3wA0loE2tFv4c8zv3SVJ"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1780284688",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "125ad2ab-1627-4789-b933-9df8245fdaaf",
            "value": "11264"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vhash",
            "timestamp": "1780284688",
            "to_ids": true,
            "type": "vhash",
            "uuid": "663ed985-8cee-4ff1-93c5-b7d7392c1877",
            "value": "3140365515180828400a0"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1780284688",
            "to_ids": true,
            "type": "filename",
            "uuid": "c8d34bbd-4c18-4906-86d1-c51c35284614",
            "value": "LoadLibrary.dll"
          },
          {
            "category": "Other",
            "comment": "Checked: 01/06/2026\nLast-scan\t:  29/05/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1780284688",
            "to_ids": false,
            "type": "text",
            "uuid": "b49ceaea-d909-49ad-a835-51a5e47ea544",
            "value": "BLUEBEAM\r\nType Description: Win32 DLL\nMicrosoft: Trojan:Win32/Casdet!rfn\nVT Total Detection:44/71\nFirst Submission:2025-07-25T08:14:34.000000+00:00\nLast Submission:2026-05-28T10:46:12.000000+00:00"
          }
        ]
      }
    ]
  }
}