CVE-2019-18935 Telerik UI Deserialization Exploited to Deploy Web Shells and a WordPress Scanner on IIS Servers

CVE-2019-18935 Telerik UI Deserialization Exploited to (TL-2026-2726) is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-09-28. It has no confirmed attribution, affects Progress Software Telerik UI for ASP.NET AJAX, references 2 CVEs (CVE-2019-18935, CVE-2017-11317), maps to 16 MITRE ATT&CK techniques (T1027, T1033, T1057), and is covered by 9 detection rules and 30 indicators of compromise.

Key facts for TL-2026-2726

Threat ID
TL-2026-2726
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-09-28
Last reviewed
2026-09-28
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
information technology, government administration, finance, unspecified internet-facing organizations
Target regions
Global
Detection rules
9
Indicators of compromise
30
Updates
2026-09-28 · revalidated 1× · latest source

Malware and tooling in CVE-2019-18935 Telerik UI Deserialization Exploited to

Malware and tooling: Godzilla Webshell, JuicyPotato, xmrig, PrintSpoofer, SweetPotato, Telegram Bot API

AhnLab ASEC documented two ongoing attack cases exploiting the CVE-2019-18935 .NET deserialization vulnerability in Telerik UI for ASP.NET AJAX (RadAsyncUpload component, versions prior to 2020.1.114) on unpatched Windows IIS servers. One campaign installed a memory-resident Godzilla-style web shell and the SweetPotato privilege-escalation tool after gaining w3wp.exe-level code execution; a second campaign deployed a Rust-based WordPress vulnerability scanner for reconnaissance.

How CVE-2019-18935 Telerik UI Deserialization Exploited to works

Progress Telerik UI for ASP.NET AJAX contains a critical .NET deserialization vulnerability (CVE-2019-18935, CVSS 3.1 9.8) in the RadAsyncUpload file-upload handler, present in versions from 2011.1.315 through 2019.3.1023 (fixed default type whitelisting shipped in 2020.1.114 / R1 2020). Exploitation typically chains CVE-2017-11317, which breaks the hard-coded AES key protecting RadAsyncUpload's encrypted `rauPostData` configuration parameter (default value `PrivateKeyForEncryptionOfRadAsyncUploadConfiguration`), letting an attacker forge and decrypt the parameter, upload an arbitrary mixed-mode assembly to a writable path, and then submit a second crafted request that deserializes a `System.Configuration.Install.AssemblyInstaller` gadget pointed at that assembly's `Path` property. When deserialized, the CLR loads the DLL and invokes its `DllMain`, yielding remote code execution in the context of the IIS worker process `w3wp.exe`.

AhnLab's ASEC documented two distinct, ongoing attack cases against unpatched IIS servers exploiting this chain. In the first, the attacker executed a reverse shell that opened a Windows socket back to a remote server at 206.82.6[.]22:80, redirected the socket as stdin/stdout/stderr, and spawned `cmd.exe` for interactive remote command execution. The attacker then queried the host (hostname, user privileges, running processes) before deploying SweetPotato, a local-service-to-SYSTEM privilege-escalation tool that bundles RottenPotato, JuicyPotato, and PrintSpoofer-style Print Spooler RPC abuse: it stands up a fake named pipe, forces the SYSTEM-privileged spooler service to connect to it via `RpcRemoteFindFirstPrinterChangeNotificationEx()`, and impersonates the resulting SYSTEM token via `SeImpersonatePrivilege`/`SeAssignPrimaryTokenPrivilege` to launch an elevated process. With SYSTEM access, the attacker installed a Godzilla-style memory-resident web shell: a DLL (observed as `godmemshell.Dll`) is injected into the Telerik ASP.NET application, where it registers a malicious `VirtualPathProvider` handler that serves a virtual ASPX endpoint existing only in worker-process memory, with no file ever written to disk. The web shell receives AES-encrypted .NET payloads over HTTP, decrypts and JIT-loads them in memory, stores session state in cookies, and re-encrypts responses before returning them, giving the operator persistent, largely fileless command execution, file transfer, and (per public Godzilla tooling) Mimikatz/PetitPotam-class post-exploitation capability.

In the second, separate attack case, the actor used the same CVE-2019-18935 initial-access vector to deploy a purpose-built Rust binary that functions as an internet-wide WordPress reconnaissance scanner. After compromise, the tool retrieves a candidate target list from a remote server (observed fetching `Ins.txt` from 65.98.5[.]158:31337) and asynchronously probes roughly 53 candidate URL paths per host looking for an exposed, unfinished WordPress installation/configuration page (`/wp-admin/setup-config.php` or `/wp-admin/install.php`) that would allow an unauthenticated attacker to complete setup and seize the site. Additional scanner configuration and target lists were retrieved from 2.59.133[.]147:31338 (`ins.txt`, `sm.json`) and 45.138.16[.]187:31337 (`bb.json`, `cofuz.json`). Results — vulnerable URLs and their public IPs — are exfiltrated as a `red.txt` attachment sent via the Telegram Bot API, using Telegram as a low-friction, encrypted-by-default C2/exfiltration channel that blends into normal HTTPS traffic.

CVE-2019-18935 has a long history of in-the-wild abuse: CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03 and notes it has been used in ransomware campaigns; Red Canary's Blue Mockingbird activity cluster (documented May 2020, active since at least December 2019) exploited the same flaw to drop XMRig Monero-mining DLLs via the `Telerik.Web.UI.WebResource.axd` endpoint, persisting via COR_PROFILER COM hijacking, modified Windows services, and scheduled tasks; and CISA/FBI/MS-ISAC's joint advisory AA23-074A (published 2023-03-15) documented exploitation of the same vulnerability against a U.S. federal civilian executive branch IIS server between November 2022 and January 2023 by two separate intrusion sets, including the cybercriminal group XE Group. ASEC's current reporting states that unpatched-Telerik attack cases 'continue to be observed,' and does not attribute the two 2026 cases to a named actor.

MITRE ATT&CK techniques used in TL-2026-2726

Defense Evasion

T1027 Obfuscated Files or Information; T1620 Reflective Code Loading

Discovery

T1033 System Owner/User Discovery; T1057 Process Discovery; T1082 System Information Discovery

Execution

T1059.001 PowerShell; T1059.003 Windows Command Shell

Command and Control

T1071.001 Web Protocols; T1102.002 Bidirectional Communication; T1105 Ingress Tool Transfer; T1573.001 Symmetric Cryptography

Privilege Escalation

T1134.001 Token Impersonation/Theft

Initial Access

T1190 Exploit Public-Facing Application

Persistence

T1505.003 Web Shell

Exfiltration

T1567 Exfiltration Over Web Service

Reconnaissance

T1595.002 Vulnerability Scanning

Affected products and versions in CVE-2019-18935 Telerik UI Deserialization Exploited to

  • Progress Software — Telerik UI for ASP.NET AJAX
    Vulnerable versions: 2011.1.315 through 2019.3.1023 (RadAsyncUpload prior to default type whitelisting)
    Fixed in: 2020.1.114 (R1 2020) and later

Remediation for CVE-2019-18935 Telerik UI Deserialization Exploited to

Patches

  • Progress Telerik UI for ASP.NET AJAX R1 2020 (2020.1.114) or later

Immediate actions

  • Upgrade Telerik UI for ASP.NET AJAX to version 2020.1.114 (R1 2020) or later, which enables RadAsyncUpload type whitelisting by default
  • If immediate upgrade is not possible, explicitly enable RadAsyncUpload type whitelisting per Telerik/Progress security guidance
  • Block or closely monitor outbound connections from IIS worker processes (w3wp.exe) to non-business destinations, including the identified C2 IPs 206.82.6.22, 65.98.5.158, 2.59.133.147, and 45.138.16.187
  • Hunt for anomalous w3wp.exe child processes (cmd.exe) and unexpected in-memory .NET assembly loads consistent with a memory-resident web shell

Workarounds

  • Restrict or disable the RadAsyncUpload handler if patching is not immediately possible
  • Restrict access to Telerik.Web.UI.WebResource.axd and related resource handlers at the web server or WAF layer
  • Remove default/placeholder WordPress installations that expose /wp-admin/setup-config.php or /wp-admin/install.php to the internet

Longer-term hardening

  • Deploy EDR/memory-forensics tooling capable of inspecting IIS worker-process memory for injected .NET assemblies and rogue VirtualPathProvider registrations, since the Godzilla-style shell writes no file to disk
  • Apply least-privilege configuration to IIS application pool identities to reduce the impact of Print-Spooler-based token-impersonation privilege escalation (SweetPotato/PrintSpoofer)
  • Disable or restrict the Print Spooler service on servers that do not require it to remove the SeImpersonatePrivilege abuse path used by Potato-family tools
  • Maintain a vulnerability-management process that also remediates CVE-2017-11317, which is a common prerequisite for defeating RadAsyncUpload's encryption and exploiting CVE-2019-18935
  • Segment externally facing WordPress installations from IIS/Telerik hosts and remove exposed setup/install pages to deny reconnaissance value to compromised-host-launched scanners

CVEs associated with CVE-2019-18935 Telerik UI Deserialization Exploited to

CVE-2019-18935, CVE-2017-11317

Weaknesses (CWE) in CVE-2019-18935 Telerik UI Deserialization Exploited to

CWE-502

Timeline of CVE-2019-18935 Telerik UI Deserialization Exploited to

  • CVE-2019-18935 is reserved as an identifier for the Telerik UI RadAsyncUpload .NET deserialization vulnerability.
  • Bishop Fox publishes technical details of CVE-2019-18935, the .NET deserialization RCE in Telerik UI for ASP.NET AJAX's RadAsyncUpload handler.
  • NVD publishes CVE-2019-18935 with a Critical CVSS 3.1 base score of 9.8, affecting Telerik UI for ASP.NET AJAX through 2019.3.1023.
  • Red Canary publishes research on Blue Mockingbird, an activity cluster that had been exploiting CVE-2019-18935 since at least December 2019 to deploy XMRig Monero-mining DLLs via the Telerik.Web.UI.WebResource.axd endpoint.
  • The Australian Cyber Security Centre issues Advisory 2020-008 documenting active exploitation of Telerik UI vulnerabilities, including CVE-2019-18935, against government and commercial targets.
  • CISA adds CVE-2019-18935 to the Known Exploited Vulnerabilities Catalog, noting it has been used in ransomware campaigns.
  • Per CISA AA23-074A, a threat actor (TA1) begins reconnaissance against a U.S. federal civilian executive branch IIS server later found exploited via CVE-2019-18935, using C2 infrastructure at 137.184.130.162 and 45.77.212.12.
  • CISA identifies the start of a window (through early January 2023) in which indicators of compromise tied to CVE-2019-18935 exploitation appear at a federal civilian executive branch agency, involving a second actor identified as the group XE Group.
  • CISA, the FBI, and MS-ISAC jointly publish advisory AA23-074A and analysis report AR23-074A detailing exploitation of CVE-2019-18935 against a U.S. government IIS server.
  • In the second ASEC-documented case, the attacker exploits CVE-2019-18935 to run a Rust-based WordPress vulnerability scanner that retrieves target lists from 65.98.5.158, 2.59.133.147, and 45.138.16.187, and exfiltrates scan results (red.txt) via the Telegram Bot API.
  • In the first ASEC-documented case, the attacker exploits CVE-2019-18935 for a reverse shell to 206.82.6.22:80, performs host discovery, escalates privileges via SweetPotato/PrintSpoofer-style Print Spooler abuse, and installs the memory-resident godmemshell.Dll Godzilla web shell.
  • AhnLab ASEC publishes analysis of two ongoing, unattributed attack cases exploiting CVE-2019-18935 against unpatched IIS servers: one installing a Godzilla-style memory web shell and the SweetPotato privilege-escalation tool, the other deploying a Rust-based WordPress vulnerability scanner.

Update history for TL-2026-2726

Sources cited for CVE-2019-18935 Telerik UI Deserialization Exploited to

More in vulnerability

Detection coverage for TL-2026-2726

As of 2026-09-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2726 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats