216.73.217.22

SharePoint Zero-Day Exploit (ToolShell) - Network Infrastructure Mapping

· Published 02/08/2025 10:18 · Modified 04/08/2025 09:19

Export JSON

Essential information

Published
02/08/2025 10:18
Modified
04/08/2025 09:19
Tags
2025-08-02 CVE-2025-49704 CVE-2025-49706 CVE-2025-53770 CVE-2025-53771 chinese threat actors cloud infrastructure mapp network mapping reconnaissance sharepoint telecommunication abuse warlock ransomware webshell zero-day
Related entities
1 intrusion sets (apt), 16 techniques (mitre), 1 malware, 15 others

Description

have been exploiting vulnerabilities in servers, known as ToolShell, affecting nearly 150 organizations worldwide. The attacks, attributed to groups like Linen Typhoon and Violet Typhoon, began as early as July 17, 2025, targeting government agencies, critical infrastructure, universities, and private enterprises. The exploitation involved chaining multiple vulnerabilities and deploying tools. Attackers utilized a diverse network infrastructure, including cloud services and VPNs across multiple countries, to obscure their origin. The campaign highlights the sophisticated tactics employed by Chinese actors in abusing global telecommunication and for cyber espionage operations.

External references