ToolShell Exploit: Critical SharePoint Zero-Day Threatens Global Enterprises
ID: 5a0e9b70-6638-5471-b38f-9259ae90d793
STIX ID: report--5a0e9b70-6638-5471-b38f-9259ae90d793
Feed Name: Recorded Future Blog
Recorded Future warns of an active zero-day exploit chain dubbed "ToolShell" targeting on-premises Microsoft SharePoint servers via CVE-2025-53770 and CVE-2025-53771; successful exploitation yields remote code execution and theft of ASP.NET ValidationKey/DecryptionKey enabling persistent access even after patching. The campaign has been observed in the wild (hundreds of victims reported), includes in-memory payloads that evade static detection, associated web shells and malware samples, attribution to multiple Chinese state-sponsored groups, and comes with YARA/Nuclei detection rules, IOCs, and mitigation recommendations including cryptographic key rotation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
