Executive Summary
In late 2025 and early 2026, threat actors targeted KnowledgeDeliver, a Learning Management System (LMS) popular in Japan, by exploiting a critical vulnerability (CVE-2026-5426) caused by identical pre-shared ASP.NET machine keys across deployments. This zero-day allows unauthenticated Remote Code Execution (RCE) via malicious ViewState payloads, enabling attackers to gain control over web servers without valid credentials.
Following initial exploitation, attackers deployed the BLUEBEAM (Godzilla) in-memory web shell within the IIS worker process and modified application JavaScript files to prompt users to download fake security updates. This social engineering tactic led to Cobalt Strike BEACON infections on user workstations. The use of target-specific encryption keys for the Cobalt Strike payloads suggests a deliberate and tailored approach to the targeted organizations.
This campaign underscores the high risk of standardized deployment templates using hardcoded secrets. Organizations using KnowledgeDeliver versions deployed before February 24, 2026, are at significant risk and must immediately rotate their ASP.NET machine keys to prevent further exploitation.
