logo

ToolShell: An all-you-can-eat buffet for threat actors

ID: 07a935f1-695e-514d-9d88-38e6ec08a94f

STIX ID: report--07a935f1-695e-514d-9d88-38e6ec08a94f

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
90/100

Date Published: 2025-07-24

Date Updated: 2026-05-01

...
...

ESET Research observed active in-the-wild exploitation of the ToolShell chain (CVE-2025-53770, CVE-2025-53771 plus CVE-2025-49704 and CVE-2025-49706) against on-premises SharePoint Server beginning July 17, 2025; attackers deployed ASP webshells (notably spinstall0.aspx / MSIL/Webshell.JS and ghostfile*.aspx), multiple IP-based attack sources were tracked worldwide, IoCs and sample hashes were published, and telemetry indicates both opportunistic cybercriminals and China-aligned APTs (including a LuckyMouse-associated backdoor) leveraged the flaws — Microsoft released patches on July 22 and ESET recommends applying updates, enabling AMSI, and rotating ASP.NET machine keys.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.