216.73.217.22

Inside The ToolShell Campaign

· Published 25/07/2025 20:49 · Modified 28/07/2025 09:13

Export JSON

Essential information

Published
25/07/2025 20:49
Modified
28/07/2025 09:13
Tags
2025-07-25 CVE-2025-49704 CVE-2025-49706 CVE-2025-53770 CVE-2025-53771 exploit chain fileless ghostwebshell keysiphon remote code execution sharepoint toolshell zero-day
Related entities
10 techniques (mitre), 2 malware

Description

FortiGuard Labs has identified a new called '' targeting on-premises Microsoft servers. This attack combines two previously patched vulnerabilities ( and ) with two variants ( and ) to achieve . The campaign uses sophisticated tools like , a ASP.NET web shell for remote access, and , which collects system information and application secrets. Active exploitation demonstrates 's status as a high-value target and the rapid weaponization of vulnerabilities. FortiGuard Labs has released protective measures and recommends swift patching, layered security, and thorough log review to mitigate risks.

External references