Chinese hackers have reportedly exploited the ToolShell vulnerability (CVE-2025-53770) in on-premises Microsoft SharePoint servers to attack governments, universities, telecom providers, and financial institutions. The exploit chain emerged as a critical zero-day in mid-July and prompted immediate security updates from Microsoft.

What is ToolShell and why is it so dangerous?
ToolShell is not a simple bug — it is a workaround for CVE-2025-49706 and CVE-2025-49704, two flaws that Viettel Cyber Security researchers demonstrated at the Pwn2Own Berlin hacking competition in May. The vulnerabilities could be exploited remotely, without authentication, to execute code and gain full file system access.
See also: Hackers sell Monolock Ransomware on Dark Web forums
Which targets were hit and how did the attackers proceed?
According to reports from Symantec/Broadcom and other security research groups, the attacks targeted organizations in the Middle East, Africa, South America, the US and Europe — from telecommunications providers and government departments to universities and financial institutions. Specifically, the targets include:
- A telecommunications service provider in the Middle East
- Two government departments in an African country
- Two government agencies in South America
- A university in the United States
- A state-owned technology organization in Africa
- A Middle Eastern government department
- A European financial company

The attackers started by installing webshells (July 21), proceeded to DLL sideloading backdoors like Zingdoor , and then deployed trojans like ShadowPad, loaders (KrustyLoader), and finally the post-exploitation framework Sliver . The loadings were sometimes done via legitimate executables (Trend Micro, BitDefender), making detection difficult .
See also: PassiveNeuron APT uses Neursite and NeuralExecutor
Connection with Chinese groups and cause for concern
Microsoft previously stated that ToolShell was used by three Chinese threat groups, Budworm/Linen Typhoon, Sheathminer/Violet Typhoon , and the Storm-2603/Warlock ransomware.
Analysts such as Recorded Future and Unit42 have also identified various tools associated with the Chinese threat ecosystem. The attacks were not unique — they show organization, tool reuse, and speed in the post-exploit chain, which increases the risk of large-scale breaches or ransomware.
Final stages of attack: From credential dumping to domain takeover
After gaining access, the attackers performed credential dumping (ProcDump, Minidump, LsassDumper), PetitPotam-style exploits for domain compromise, and used utility tools such as Certutil, Revsocks, and GoGo Scanner for data extraction and command-and-control.
See also: Vidar 2.0: New version, increased risk for users

What should managers and organizations do now?
The immediate message is clear: apply Microsoft patches immediately to all supported on-prem SharePoint, rotate ASP.NET machine keys, enable endpoint detection/EDR, and look for indicators of compromise such as webshells and unusual DLL sideloading. Organizations without on-prem SharePoint (e.g., SharePoint Online) are not affected — but those maintaining internet-exposed servers should act immediately.
Why ToolShell should worry us
ToolShell shows how quickly attackers can exploit a combination of vulnerabilities — even those presented in competitions like Pwn2Own — and turn a server into an advanced espionage or extortion mechanism. Fighting such chains requires rapid information dissemination, systematic threat-hunting, and cooperation between software vendors, governments, and security researchers.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
