logo

ToolShell Exploit: Critical SharePoint Zero-Day Threatens Global Enterprises

ID: 5a0e9b70-6638-5471-b38f-9259ae90d793

STIX ID: report--5a0e9b70-6638-5471-b38f-9259ae90d793

Feed Name: Recorded Future Blog

Threat Score
90/100

Date Published: 2025-07-23

Date Updated: 2026-04-28

...
...

Recorded Future warns of an active zero-day exploit chain dubbed "ToolShell" targeting on-premises Microsoft SharePoint servers via CVE-2025-53770 and CVE-2025-53771; successful exploitation yields remote code execution and theft of ASP.NET ValidationKey/DecryptionKey enabling persistent access even after patching. The campaign has been observed in the wild (hundreds of victims reported), includes in-memory payloads that evade static detection, associated web shells and malware samples, attribution to multiple Chinese state-sponsored groups, and comes with YARA/Nuclei detection rules, IOCs, and mitigation recommendations including cryptographic key rotation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.