Gold Melody IAB Exploits Exposed ASP.NET Machine Keys for Unauthorized Access to Targets
A campaign that uses stolen ASP.NET machine keys to gain unauthorized access to companies and sell that access to other threat actors has been linked to the Initial Access Broker (IAB) known as Gold Melody.
Under the designation TGR-CRI-0045—where "TGR" stands for "temporary group" and "CRI" for "criminal motivation"—Palo Alto Networks Unit 42 is monitoring the activities. Prophet Spider and UNC961 are other names for the hacker outfit, while ToyMaker, an initial access broker, also uses one of its tools.
According to academics Tom Marsden and Chema Garcia, the group appears to use an opportunistic strategy, but it has targeted companies in the financial services, manufacturing, wholesale and retail, high technology, transportation, and logistics sectors in both Europe and the Unite...

