Distribution of Godzilla WebShell Abusing ViewState (Targeting Financial Sector)

Distribution of Godzilla WebShell Abusing ViewState (Targeting Financial Sector)

Overview   AhnLab SEcurity intelligence Center (ASEC) has recently detected an attack targeting financial sector companies. The threat actor primarily targeted ASP.NET environments with vulnerable configurations, abusing the ViewState feature supported by ASP.NET.  ViewState is a fundamental feature of ASP.NET that allows the handling of user input or other data