SharePoint Zero-Day Exploit (ToolShell) - Network Infrastructure Mapping
Essential information
- Published
- 02/08/2025 10:18
- Modified
- 04/08/2025 09:19
- Tags
- 2025-08-02 CVE-2025-49704 CVE-2025-49706 CVE-2025-53770 CVE-2025-53771 chinese threat actors cloud infrastructure mapp network mapping reconnaissance sharepoint telecommunication abuse warlock ransomware webshell zero-day
- Related entities
- 1 intrusion sets (apt), 16 techniques (mitre), 1 malware, 15 others
Description
Chinese threat actors have been exploiting zero-day vulnerabilities in SharePoint servers, known as ToolShell, affecting nearly 150 organizations worldwide. The attacks, attributed to groups like Linen Typhoon and Violet Typhoon, began as early as July 17, 2025, targeting government agencies, critical infrastructure, universities, and private enterprises. The exploitation involved chaining multiple vulnerabilities and deploying reconnaissance tools. Attackers utilized a diverse network infrastructure, including cloud services and VPNs across multiple countries, to obscure their origin. The campaign highlights the sophisticated tactics employed by Chinese actors in abusing global telecommunication and cloud infrastructure for cyber espionage operations.