216.73.216.6

ToolShell: An all-you-can-eat buffet for threat actors

· Published 12/08/2025 10:45 · Modified 12/08/2025 11:19

Export JSON

Essential information

Published
12/08/2025 10:45
Modified
12/08/2025 11:19
Tags
2025-08-12 CVE-2025-49704 CVE-2025-49706 CVE-2025-53770 CVE-2025-53771 apt backdoor china-aligned exploitation msil/webshell.js sharepoint toolshell vulnerability webshell zero-day
Related entities
1 vulnerabilities (cve), 20 observables, 1 intrusion sets (apt), 4 techniques (mitre), 1 malware, 2 others

Description

A set of vulnerabilities in Server, dubbed , has been exploited in the wild since July 17, 2025. The vulnerabilities, and , allow remote code execution and server spoofing, affecting on-premises servers. Attackers have been chaining these with previously patched vulnerabilities to bypass authentication and deploy webshells. The attacks have been observed globally, with the US being the most targeted country. Various threat actors, including groups, have been exploiting . A associated with LuckyMouse was detected on a compromised machine in Vietnam. The ongoing attacks are expected to continue, targeting high-value government organizations and other vulnerable systems.

External references