HomeSecuritySharepoint: Chinese Target Organizations Through ToolShell Vulnerability

Sharepoint: Chinese Target Organizations Through ToolShell Vulnerability

Chinese hackers have reportedly exploited the ToolShell vulnerability (CVE-2025-53770) in on-premises Microsoft SharePoint servers to attack governments, universities, telecom providers, and financial institutions. The exploit chain emerged as a critical zero-day in mid-July and prompted immediate security updates from Microsoft.

Sharepoint ToolShell

What is ToolShell and why is it so dangerous?

ToolShell is not a simple bug — it is a workaround for CVE-2025-49706 and CVE-2025-49704, two flaws that Viettel Cyber ​​Security researchers demonstrated at the Pwn2Own Berlin hacking competition in May. The vulnerabilities could be exploited remotely, without authentication, to execute code and gain full file system access.

See also: Hackers sell Monolock Ransomware on Dark Web forums

Which targets were hit and how did the attackers proceed?

According to reports from Symantec/Broadcom and other security research groups, the attacks targeted organizations in the Middle East, Africa, South America, the US and Europe — from telecommunications providers and government departments to universities and financial institutions. Specifically, the targets include:

  • A telecommunications service provider in the Middle East
  • Two government departments in an African country
  • Two government agencies in South America
  • A university in the United States
  • A state-owned technology organization in Africa
  • A Middle Eastern government department
  • A European financial company
Sharepoint: Chinese Target Organizations Through ToolShell Vulnerability

The attackers started by installing webshells (July 21), proceeded to DLL sideloading backdoors like Zingdoor , and then deployed trojans like ShadowPad, loaders (KrustyLoader), and finally the post-exploitation framework Sliver . The loadings were sometimes done via legitimate executables (Trend Micro, BitDefender), making detection difficult .

See also: PassiveNeuron APT uses Neursite and NeuralExecutor

Connection with Chinese groups and cause for concern

Microsoft previously stated that ToolShell was used by three Chinese threat groups, Budworm/Linen Typhoon, Sheathminer/Violet Typhoon , and the Storm-2603/Warlock ransomware.

Analysts such as Recorded Future and Unit42 have also identified various tools associated with the Chinese threat ecosystem. The attacks were not unique — they show organization, tool reuse, and speed in the post-exploit chain, which increases the risk of large-scale breaches or ransomware.

Final stages of attack: From credential dumping to domain takeover

After gaining access, the attackers performed credential dumping (ProcDump, Minidump, LsassDumper), PetitPotam-style exploits for domain compromise, and used utility tools such as Certutil, Revsocks, and GoGo Scanner for data extraction and command-and-control.

See also: Vidar 2.0: New version, increased risk for users

Sharepoint: Chinese Target Organizations Through ToolShell Vulnerability

What should managers and organizations do now?

The immediate message is clear: apply Microsoft patches immediately to all supported on-prem SharePoint, rotate ASP.NET machine keys, enable endpoint detection/EDR, and look for indicators of compromise such as webshells and unusual DLL sideloading. Organizations without on-prem SharePoint (e.g., SharePoint Online) are not affected — but those maintaining internet-exposed servers should act immediately.

Why ToolShell should worry us

ToolShell shows how quickly attackers can exploit a combination of vulnerabilities — even those presented in competitions like Pwn2Own — and turn a server into an advanced espionage or extortion mechanism. Fighting such chains requires rapid information dissemination, systematic threat-hunting, and cooperation between software vendors, governments, and security researchers.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS