CTIPilot
← Back to the live brief
NOTABLECVE-2019-18935exploitedNATOB2vulnerability

CVE-2019-18935, Progress Telerik UI for ASP.NET AJAX: a patched-since-2020 deserialization RCE still exploited, now via an in-memory Godzilla web shell registered on ASP.NET's VirtualPathProvider

AhnLab documents two fresh, unrelated intrusions still riding a six-year-old Telerik deserialization bug into unpatched IIS servers

Analysis

AhnLab's ASEC documents two separate, unrelated 2026 intrusions in Korea that both exploit CVE-2019-18935, a .NET deserialization vulnerability in the RadAsyncUpload file-upload feature of Telerik UI for ASP.NET AJAX, patched by the vendor since version 2020.1.114 but still reachable on unpatched IIS deployments; successful exploitation executes code with the privileges of the w3wp.exe worker-process account (AhnLab ASEC, 2026-09-27). In the first case, the attacker used the flaw to launch a reverse shell, ran basic reconnaissance, and deployed modified Potato-family token-impersonation tools, including a web-shell-adapted build of SweetPotato, to escalate to SYSTEM. The intrusion culminated in a memory-resident, file-less web shell: a payload DLL locates the IIS worker thread that has already loaded Telerik.Web.UI, loads an embedded module into that process's memory, and registers a malicious request handler directly with ASP.NET's VirtualPathProvider extensibility point, so the web shell runs entirely in server memory with no .aspx file ever written to disk (AhnLab ASEC, 2026-09-27). The installed shell follows the Godzilla web-shell protocol: it distinguishes actions via an HTTP request's Type header, decrypts the request body, caches an attacker-supplied .NET payload in a cookie-bound session on first contact, and re-invokes that cached payload on each later request: an arbitrary, extensible in-memory .NET execution primitive that leaves minimal on-disk forensic trace.

The second, unrelated intrusion used the same CVE purely to launch a Rust-based reconnaissance scanner: it pulls a target list from an operator-controlled server, asynchronously probes each target across candidate URL paths for exposed WordPress installer/configuration pages, and reports any hit back to the operator over the Telegram Bot API, without dropping a reverse shell or web shell on the compromised Telerik host itself (AhnLab ASEC, 2026-09-27). ASEC notes this CVE has a long exploitation history: Blue Mockingbird's 2020 Monero-mining campaign, and a 2023 CISA/FBI/MS-ISAC advisory covering US federal-agency IIS servers, underscoring that a legacy, patched-since-2020 vulnerability in a still-deployed enterprise .NET web component remains a live, low-cost initial-access vector six years after disclosure.

Detection and hunting. In process-creation telemetry, alert on w3wp.exe spawning cmd.exe or PowerShell with no corresponding legitimate application feature to explain it; the VirtualPathProvider registration technique means no new .aspx file appears on disk, so file-integrity monitoring over the web root will miss this shell entirely; in-memory module-loading detection (unusual modules loaded into the IIS worker process, or EDR visibility into .NET AppDomain assembly loads) is the telemetry class that catches it. The Godzilla protocol's own signature is a request carrying a non-standard Type header to an otherwise ordinary-looking Telerik endpoint. For the second intrusion, look for outbound connections from an IIS host to api.telegram.org, a pattern with no legitimate counterpart on a production Telerik/IIS server.

Triage: SweetPotato and other Potato-family tools are dual-use privilege-escalation utilities also used in authorized red-team engagements, so the discriminator is context: their invocation from a web-shell process rather than an interactive administrative session, and their appearance immediately following exploitation of an unpatched RadAsyncUpload endpoint rather than a scheduled maintenance task.

Cited evidence

CVE-2019-18935 is a .NET deserialization vulnerability in RadAsyncUpload, a file upload feature; if exploited, a threat actor can perform remote code execution with the privileges of the w3wp.Exe process on an IIS web server.

It then registers a malicious request-handling function with ASP.NET's VirtualPathProvider, enabling the web shell to run in the web server process's memory without requiring a separate .Aspx file.

The scanner is a Rust-based tool that receives a list of targets from a remote server and asynchronously scans for URLs leading to WordPress installation and configuration pages.

AhnLab ASEC 2026-09-27

Sources1

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.