logo

CVE-2025–53770/TOOLSHELL: HUNTING DOWN THE ATTACKER TECHNIQUES & VICTIMS

ID: 540ea00e-e191-530d-9693-ad04d5a26927

STIX ID: report--540ea00e-e191-530d-9693-ad04d5a26927

Feed Name: THE RAVEN FILE

Threat Score
78/100

Date Published: 2025-07-22

Date Updated: 2026-04-19

Author: RakeshKrish

...
...

This investigative report documents active exploitation of CVE-2025-53770 (a critical SharePoint deserialization flaw), observed as early as 25 June 2025, and details the exploit chain, malicious artifacts (including cve.ps1 and other payload MD5s), CUP protocol spoofing used as a decoy, abuse of Microsoft Edge utility processes for sandbox evasion, YARA detection rules, and a set of domains, IPs, mutexes and shell commands to aid threat hunting and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.