Chinese hackers exploit ToolShell in SharePoint, targeting global infrastructure.

This title was summarized by AI from the post below.

🚨 ToolShell Exploits in Microsoft SharePoint: A Global Threat Landscape Unfolds 🌍 Chinese threat actors have weaponized the ToolShell vulnerability (CVE-2025-53770) in on-prem SharePoint servers, targeting critical infrastructure across four continents, including government agencies, universities, telecom providers, and finance firms. 🔍 Key Technical Insights: ToolShell is a zero-day RCE flaw that bypasses CVE-2025-49706 and CVE-2025-49704. Attackers used webshells for persistent access, followed by DLL side-loading of: 🛠️ Zingdoor (Go-based backdoor) 🐛 ShadowPad Trojan 🦀 KrustyLoader (Rust-based loader) 🧬 Sliver (post-exploitation framework) Legitimate executables from Trend Micro and BitDefender were abused for stealth. Credential dumping via ProcDump, Minidump, and LsassDumper. PetitPotam (CVE-2021-36942) used for domain compromise. Living-off-the-land tools included Certutil, GoGo Scanner, and Revsocks. 📊 Symantec’s report reveals a broader set of Chinese APTs involved than previously known, including Salt Typhoon, Budworm, Sheathminer, and Storm-2603. 🔐 This campaign underscores the urgency of patching vulnerable SharePoint instances and monitoring for lateral movement and post-exploitation frameworks. #CyberSecurity #Infosec #ThreatIntel #APT #SharePoint #ToolShell #ZeroDay #RCE #Microsoft #DLLSideLoading #RustMalware #CredentialDumping #LivingOffTheLand #Symantec #BlueReport2025 #CVE2025 #SecurityOps #IncidentResponse #SOC #ThreatHunting

To view or add a comment, sign in

Explore content categories