Menu
Browse

Vulnerable Telerik UI systems

Primary URL Location Industry
www[.]telerik[.]com
Country United States of America
Technology Icon
Technology
Profile

Vulnerable Telerik UI systems refers to the Telerik UI for ASP.NET AJAX product line, which provides a suite of user‑interface components for building interactive web applications. The organisation is headquartered in the United States of America. Its components are used by developers and enterprises to create web‑based interfaces for a variety of applications. The offering includes controls such as data grids, charts, schedulers, and editors that integrate directly with ASP.NET AJAX frameworks. These components are distributed as part of the Telerik UI suite for ASP.NET AJAX.

A distinguishing attribute of this organisation is that its UI component suite is widely used in enterprise web applications, as demonstrated by the June 2022 attack. In June 2022, a threat actor exploited a critical deserialization vulnerability in Telerik UI for ASP.NET AJAX to achieve remote code execution. The attackers first acquired encryption keys through auxiliary vulnerabilities or application weaknesses. They then leveraged a proof‑of‑concept exploit to compile malicious DLLs that were executed via the web application’s processes. Persistence was established by creating Group Policy Objects that scheduled tasks containing encoded PowerShell scripts, which evaded detection while loading in‑memory payloads. The operation culminated in the deployment of cryptocurrency miners designed to hijack system resources for Monero mining. This activity mirrored previous campaigns attributed to the same threat group. Although the primary objective was cryptojacking, the installed Cobalt Strike beacons provided a foothold for potential further network compromise. Such follow‑on actions could include data exfiltration, lateral movement, or the deployment of ransomware. The incident underscored how a flaw in a widely used UI library could be chained to achieve significant impact on affected organisations.

Incidents
Linked incidents available to members
1 incident