logo

3 China Nation-State Actors Target SharePoint Bugs

ID: 8a19f7fc-9032-526d-9aeb-96f1a85b41f2

STIX ID: report--8a19f7fc-9032-526d-9aeb-96f1a85b41f2

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2025-07-22

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Microsoft and security researchers observed China-linked APTs (Linen Typhoon, Violet Typhoon, Storm-2603) exploiting multiple SharePoint zero-days (CVE-2025-49706, CVE-2025-49704 and later CVE-2025-53770/53771) via an attack chain dubbed "ToolShell" to deploy PowerShell-based backdoors, webshells and fileless malware and to exfiltrate keys; vendors advise immediate patching, credential/machine-key rotation, and hunting for provided IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.