CVE-2019-18935, Progress Telerik UI for ASP.NET AJAX: a patched-since-2020 deserialization RCE still exploited, now via an in-memory Godzilla web shell registered on ASP.NET's VirtualPathProvider
AhnLab documents two fresh, unrelated intrusions still riding a six-year-old Telerik deserialization bug into unpatched IIS servers
Analysis
AhnLab's ASEC documents two separate, unrelated 2026 intrusions in Korea that both exploit CVE-2019-18935, a .NET
deserialization vulnerability in the RadAsyncUpload file-upload feature of Telerik UI for ASP.NET AJAX, patched by
the vendor since version 2020.1.114 but still reachable on unpatched IIS deployments; successful exploitation
executes code with the privileges of the w3wp.exe worker-process account
(AhnLab ASEC, 2026-09-27). In the first case, the attacker used the flaw to
launch a reverse shell, ran basic reconnaissance, and deployed modified Potato-family token-impersonation tools,
including a web-shell-adapted build of SweetPotato, to escalate to SYSTEM. The intrusion culminated in a
memory-resident, file-less web shell: a payload DLL locates the IIS worker thread that has already loaded
Telerik.Web.UI, loads an embedded module into that process's memory, and registers a malicious request handler
directly with ASP.NET's VirtualPathProvider extensibility point, so the web shell runs entirely in server memory
with no .aspx file ever written to disk (AhnLab ASEC, 2026-09-27). The
installed shell follows the Godzilla web-shell protocol: it distinguishes actions via an HTTP request's Type
header, decrypts the request body, caches an attacker-supplied .NET payload in a cookie-bound session on first
contact, and re-invokes that cached payload on each later request: an arbitrary, extensible in-memory .NET
execution primitive that leaves minimal on-disk forensic trace.
The second, unrelated intrusion used the same CVE purely to launch a Rust-based reconnaissance scanner: it pulls a target list from an operator-controlled server, asynchronously probes each target across candidate URL paths for exposed WordPress installer/configuration pages, and reports any hit back to the operator over the Telegram Bot API, without dropping a reverse shell or web shell on the compromised Telerik host itself (AhnLab ASEC, 2026-09-27). ASEC notes this CVE has a long exploitation history: Blue Mockingbird's 2020 Monero-mining campaign, and a 2023 CISA/FBI/MS-ISAC advisory covering US federal-agency IIS servers, underscoring that a legacy, patched-since-2020 vulnerability in a still-deployed enterprise .NET web component remains a live, low-cost initial-access vector six years after disclosure.
Detection and hunting. In process-creation telemetry, alert on w3wp.exe spawning cmd.exe or PowerShell with
no corresponding legitimate application feature to explain it; the VirtualPathProvider registration technique means
no new .aspx file appears on disk, so file-integrity monitoring over the web root will miss this shell entirely;
in-memory module-loading detection (unusual modules loaded into the IIS worker process, or EDR visibility into
.NET AppDomain assembly loads) is the telemetry class that catches it. The Godzilla protocol's own signature is a
request carrying a non-standard Type header to an otherwise ordinary-looking Telerik endpoint. For the second
intrusion, look for outbound connections from an IIS host to api.telegram.org, a pattern with no legitimate
counterpart on a production Telerik/IIS server.
Triage: SweetPotato and other Potato-family tools are dual-use privilege-escalation utilities also used in authorized red-team engagements, so the discriminator is context: their invocation from a web-shell process rather than an interactive administrative session, and their appearance immediately following exploitation of an unpatched RadAsyncUpload endpoint rather than a scheduled maintenance task.
Cited evidence
CVE-2019-18935 is a .NET deserialization vulnerability in RadAsyncUpload, a file upload feature; if exploited, a threat actor can perform remote code execution with the privileges of the w3wp.Exe process on an IIS web server.
It then registers a malicious request-handling function with ASP.NET's VirtualPathProvider, enabling the web shell to run in the web server process's memory without requiring a separate .Aspx file.
The scanner is a Rust-based tool that receives a list of targets from a remote server and asynchronously scans for URLs leading to WordPress installation and configuration pages.
Sources1
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.