{"id":71201,"date":"2025-10-23T17:37:31","date_gmt":"2025-10-23T14:37:31","guid":{"rendered":"https:\/\/digitrendz.blog\/?p=71201"},"modified":"2025-10-23T17:37:35","modified_gmt":"2025-10-23T14:37:35","slug":"sharepoint-toolshell-attacks-strike-global-orgs-on-4-continents","status":"publish","type":"post","link":"https:\/\/digitrendz.blog\/z\/newswire\/technology\/71201\/sharepoint-toolshell-attacks-strike-global-orgs-on-4-continents\/","title":{"rendered":"Sharepoint ToolShell Attacks Strike Global Orgs on 4 Continents"},"content":{"rendered":"<details class=\"wp-block-details ticss-586932b6 is-layout-flow wp-block-details-is-layout-flow\"><summary>\u25bc Summary<\/summary>\n<p class=\"ticss-0c48f427 has-small-font-size wp-block-paragraph\">&#8211; Chinese hackers exploited the ToolShell vulnerability (CVE-2025-53770) in Microsoft SharePoint to target government, education, telecom, and finance sectors globally.<br>&#8211; Microsoft disclosed the actively exploited zero-day flaw on July 20 and released emergency updates the following day for on-premise SharePoint servers.<br>&#8211; The vulnerability allows remote, unauthenticated attackers to execute code and gain full file system access, building on earlier flaws demonstrated at Pwn2Own Berlin.<br>&#8211; Symantec reported that attacks involved deploying webshells, backdoors like Zingdoor and ShadowPad, and tools such as Sliver for persistence and data exfiltration.<br>&#8211; The campaign used publicly available tools and legitimate software for side-loading, indicating broader exploitation by Chinese threat actors than previously known.<br><\/p>\n<\/details>\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n<p class=\"has-drop-cap wp-block-paragraph\"><mark style=\"background-color:rgba(0, 0, 0, 0);color:#f34c3e\" class=\"has-inline-color\">A<\/mark> significant <a href=\"https:\/\/digitrendz.blog\/z\/trending-news\/171234\/seiko-usa-hacked-customer-data-stolen\/\" class=\"acp-article-link\" data-article-id=\"171234\" title=\"Seiko USA Hacked, Customer Data Stolen\" target=\"_blank\" rel=\"noopener noreferrer\">cybersecurity incident<\/a> involving the <strong>ToolShell vulnerability (CVE-2025-53770)<\/strong> in <a href=\"https:\/\/digitrendz.blog\/z\/entity\/microsoft-sharepoint\/\" class=\"acp-entity-link\" data-entity-id=\"64031\" data-entity-category=\"Technology\" title=\"Learn more about Microsoft SharePoint\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft SharePoint<\/a> has impacted organizations worldwide, with security researchers linking the activity to hacking groups operating from <a href=\"https:\/\/digitrendz.blog\/z\/entity\/china\/\" class=\"acp-entity-link\" data-entity-id=\"1912\" data-entity-category=\"Location\" title=\"Learn more about China\" target=\"_blank\" rel=\"noopener noreferrer\">China<\/a>. The flaw specifically targets on-premise SharePoint servers and was initially identified as an actively exploited zero-day on July 20. Microsoft responded by issuing emergency patches just one day later. This security gap effectively bypasses two earlier vulnerabilities, CVE-2025-49706 and CVE-2025-49704, which <a href=\"https:\/\/digitrendz.blog\/z\/entity\/viettel-cyber-security\/\" class=\"acp-entity-link\" data-entity-id=\"140570\" data-entity-category=\"Organization\" title=\"Learn more about Viettel Cyber Security\" target=\"_blank\" rel=\"noopener noreferrer\">Viettel Cyber Security<\/a> had previously demonstrated during the <a href=\"https:\/\/digitrendz.blog\/z\/entity\/pwn2own-berlin\/\" class=\"acp-entity-link\" data-entity-id=\"54136\" data-entity-category=\"Event\" title=\"Learn more about Pwn2Own Berlin\" target=\"_blank\" rel=\"noopener noreferrer\">Pwn2Own Berlin<\/a> event in May. Attackers can leverage it remotely without needing authentication, allowing them to execute arbitrary code and gain unrestricted access to the entire file system.<\/p>\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/digitrendz.blog\/z\/entity\/microsoft\/\" class=\"acp-entity-link\" data-entity-id=\"251\" data-entity-category=\"Organization\" title=\"Learn more about Microsoft\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft<\/a> has publicly attributed the exploitation of ToolShell to three distinct Chinese threat actors: Budworm (also known as Linen Typhoon), Sheathminer (Violet Typhoon), and the Storm-2603 group, which is associated with Warlock ransomware. A recent analysis from <a href=\"https:\/\/digitrendz.blog\/z\/entity\/symantec\/\" class=\"acp-entity-link\" data-entity-id=\"117644\" data-entity-category=\"Organization\" title=\"Learn more about Symantec\" target=\"_blank\" rel=\"noopener noreferrer\">Symantec<\/a>, a Broadcom company, reveals that the vulnerability was used to infiltrate a wide array of entities across four continents, including the <a href=\"https:\/\/digitrendz.blog\/z\/entity\/middle-east\/\" class=\"acp-entity-link\" data-entity-id=\"110\" data-entity-category=\"Place\" title=\"Learn more about Middle East\" target=\"_blank\" rel=\"noopener noreferrer\">Middle East<\/a>, <a href=\"https:\/\/digitrendz.blog\/z\/entity\/south-america\/\" class=\"acp-entity-link\" data-entity-id=\"12278\" data-entity-category=\"Location\" title=\"Learn more about South America\" target=\"_blank\" rel=\"noopener noreferrer\">South America<\/a>, the United States, and Africa. The tactics and malware employed in these campaigns are consistent with those used by the Chinese hacking collective known as <a href=\"https:\/\/digitrendz.blog\/z\/entity\/salt-typhoon\/\" class=\"acp-entity-link\" data-entity-id=\"32668\" data-entity-category=\"Organization\" title=\"Learn more about Salt Typhoon\" target=\"_blank\" rel=\"noopener noreferrer\">Salt Typhoon<\/a>.<\/p>\n\n<p class=\"wp-block-paragraph\">Among the confirmed victims are a telecommunications provider in the Middle East, two separate government departments in an African nation, two government bodies in South America, a university located in the United States, a state-level technology agency in <a href=\"https:\/\/digitrendz.blog\/z\/entity\/africa\/\" class=\"acp-entity-link\" data-entity-id=\"5873\" data-entity-category=\"Location\" title=\"Learn more about Africa\" target=\"_blank\" rel=\"noopener noreferrer\">Africa<\/a>, another Middle Eastern government department, and a financial services firm based in <a href=\"https:\/\/digitrendz.blog\/z\/newswire\/business\/137323\/advantest-hit-by-ransomware-attack-disrupting-chip-testing\/\" class=\"acp-article-link\" data-article-id=\"137323\" title=\"Advantest Hit by Ransomware Attack, Disrupting Chip Testing\" target=\"_blank\" rel=\"noopener noreferrer\">Europe<\/a>. Symantec\u2019s report provides a detailed timeline of the attack on the Middle Eastern telecom company, which commenced on July 21. The initial intrusion involved exploiting the SharePoint flaw to install webshells, providing the attackers with a persistent foothold inside the network.<\/p>\n\n<p class=\"wp-block-paragraph\">Subsequently, the attackers used a technique called DLL side-loading to deploy a backdoor written in Go, identified as Zingdoor. This malicious tool is capable of harvesting system information, performing various file operations, and enabling the remote execution of commands. Another side-loading operation was then used to launch what investigators believe is the <strong>ShadowPad Trojan<\/strong>, a sophisticated malware family. Following this, the threat actors deployed KrustyLoader, a tool built using the Rust programming language, which ultimately installed the Sliver open-source <a href=\"https:\/\/digitrendz.blog\/z\/topic\/post-exploitation-framework\/\" class=\"acp-topic-link\" data-topic-id=\"117707\" title=\"Explore: post-exploitation framework\" target=\"_blank\" rel=\"noopener noreferrer\">post-exploitation framework<\/a>. Notably, the side-loading procedures abused legitimate executable files from security vendors Trend Micro and BitDefender. In the South American attacks, the hackers used a file that mimicked the Symantec brand name.<\/p>\n\n<p class=\"wp-block-paragraph\">After establishing a strong presence, the attackers moved to dump credentials using tools like ProcDump, Minidump, and LsassDumper. They also leveraged the PetitPotam vulnerability (CVE-2021-36942) to further compromise the network domain. The attackers relied heavily on publicly available utilities and living-off-the-land techniques to avoid detection. These tools included Microsoft\u2019s own Certutil, the GoGo Scanner, a scanning engine often used by red teams, and Revsocks, a utility that supports data exfiltration, command-and-control communication, and maintaining persistence on infected systems.<\/p>\n\n<p class=\"wp-block-paragraph\">Symantec\u2019s investigation concludes that the exploitation of the <a href=\"https:\/\/digitrendz.blog\/z\/topic\/toolshell-vulnerability\/\" class=\"acp-topic-link\" data-topic-id=\"117703\" title=\"Explore: toolshell vulnerability\" target=\"_blank\" rel=\"noopener noreferrer\">ToolShell vulnerability<\/a> is not limited to the three groups initially identified by Microsoft. Instead, the evidence suggests a broader set of Chinese threat actors are actively using this flaw in their operations, indicating a wider and more coordinated campaign than security officials previously understood.<\/p>\n\n<p class=\"wp-block-paragraph\"><em>(Source: <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/sharepoint-toolshell-attacks-targeted-orgs-across-four-continents\/\" target=\"_blank\" rel=\"noreferrer noopener\">Bleeping Computer<\/a>)<\/em><\/p>","protected":false},"excerpt":{"rendered":"<p>The ToolShell vulnerability (CVE-2025-53770) in Microsoft SharePoint is a critical zero-day flaw that allows unauthenticated remote attackers to execute arbitrary code and access file systems, bypassing previous vulnerabilities. Microsoft attributes the exploitation to Chinese threat actors like &#8230;<\/p>\n","protected":false},"author":1,"featured_media":71200,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_themeisle_gutenberg_block_has_review":false,"cybocfi_hide_featured_image":"","footnotes":""},"categories":[6579,3297,3327,3254],"tags":[46093,43303,8492,105286,105287],"entities":[3899,45484,105290,1322,105288,3411,904,43213,692,37161,23553,105291,7226,105292,82955,1013,3672,105289],"class_list":["post-71201","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-bigtech-companies","category-cybersecurity","category-newswire","category-technology","tag-chinese-threat-actors","tag-cve-2025-53770","tag-cybersecurity-incident","tag-global-cyber-attacks","tag-sharepoint-toolshell-vulnerability","entity-africa","entity-broadcom","entity-budworm-linen-typhoon","entity-china","entity-july-20","entity-may","entity-microsoft","entity-microsoft-sharepoint","entity-middle-east","entity-pwn2own-berlin","entity-salt-typhoon","entity-sheathminer-violet-typhoon","entity-south-america","entity-storm-2603-warlock","entity-symantec","entity-united-states","entity-us","entity-viettel-cyber-security"],"_links":{"self":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/71201","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/comments?post=71201"}],"version-history":[{"count":0,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/71201\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media\/71200"}],"wp:attachment":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media?parent=71201"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/categories?post=71201"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/tags?post=71201"},{"taxonomy":"entity","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/entities?post=71201"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}