ysoserial.net is an open-source .NET deserialization payload generator used for security testing and abused in attacks against vulnerable applications. It is an exploitation tool rather than a standalone malware family. Its gadget chains produce serialized objects that trigger code execution when processed by susceptible .NET deserializers. Its View State plugin supports constructing malicious ASP.NET ViewState payloads for attacks against IIS-hosted applications, including Microsoft Exchange and SharePoint. Where ViewState integrity validation is enabled, attackers require valid validation keys to authenticate forged payloads; encrypted ViewState also requires the corresponding decryption material.
Supported gadget chains can load and execute .NET assemblies in application-worker-process memory. The ActivitySurrogateDisableTypeCheck gadget disables restrictions that otherwise prevent use of ActivitySurrogateSelector on newer .NET Framework versions. These mechanisms can support initial compromise or renewed code execution after an attacker has obtained application keys.
Obstinate Mogwai used ysoserial.net-style gadgets during attacks against a Russian telecommunications organization. Shedding Zmiy incorporated its XamlAssemblyLoadFromFile gadget into the custom BADSTATE framework used against Microsoft Exchange. Command execution, file operations, data theft, and persistent web-shell functionality in these intrusions were implemented by associated payloads and frameworks, not by ysoserial.net itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
“With the stolen keys, the attacker crafts a malicious ViewState payload using ysoserial.net or a custom serializer.”
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The structure of the observed VIEWSTATE payloads indicated that the attackers generated them using ysoserial.net.
The structure of the observed VIEWSTATE payloads indicated that the attackers generated them using ysoserial.net.
«...Shedding Zmiy используют самописный гаджет, который распаковывает и вызывает гаджет XamlAssemblyLoadFromFile из набора ysoserial.»
16 distinct techniques documented for this family, organized by ATT&CK tactic.
So we generated a payload with ysoserial.net ... -c "whoami > C:\x.txt".
ysoserial.exe -g ObjectDataProvider -f Json.Net -c "powershell -enc ..." ... PowerShell with -EncodedCommand, -enc, -ec, bypass, or unrestricted.
The provided ysoserial payload executes `cmd /c nslookup yuwewp90p365hx64wh7rumz8kzqxem.burpcollaborator.net`.
Instead of calling Process.Start() now we move on eval JScript. With JScript, we can do many things with scripting instead of spawning cmd.exe / powershell.exe.
# TTP # T1211 — Exploitation for Defense Evasion (Defense Evasion)
TypeConfuseDelegate depends on System.Configuration.Install.dll / System.Management.dll ... all available on the target.
Abuse of Deserialization for RCE: With the sysadmin API token, the attacker interacts with application API endpoints, targeting a deserialization function. By injecting a malicious payload into this process, arbitrary code execution is achieved on the server.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named offensive tool used in the described attack chain to generate .NET deserialization payloads. The fictional breach simulation also uses it to construct a payload for CVE-2026-45659. It is exploitation tooling, not a standalone infection payload.
A named offensive tool used in the described attack chain to generate .NET deserialization payloads. The fictional breach simulation also uses it to construct a payload for CVE-2026-45659. It is exploitation tooling, not a standalone infection payload.
Open-source .NET deserialization payload generator used here to craft malicious ASP.NET View State payloads (signed with leaked Machine Keys) to achieve in-memory code execution in IIS worker processes.
Offensive toolkit for generating .NET deserialization payloads. Shedding Zmiy wraps its XamlAssemblyLoadFromFile gadget inside a custom compressed and encoded gadget to load ViewStateExecutor into memory. The comparison section states that Obstinate Mogwai uses stock ysoserial gadgets, including ActivitySurrogateDisableTypeCheck and ActivitySurrogateSelectorFromFile.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.