ToolShell: An all-you-can-eat buffet for threat actors
ID: 07a935f1-695e-514d-9d88-38e6ec08a94f
STIX ID: report--07a935f1-695e-514d-9d88-38e6ec08a94f
Feed Name: WeLiveSecurity (ESET Research)
ESET Research observed active in-the-wild exploitation of the ToolShell chain (CVE-2025-53770, CVE-2025-53771 plus CVE-2025-49704 and CVE-2025-49706) against on-premises SharePoint Server beginning July 17, 2025; attackers deployed ASP webshells (notably spinstall0.aspx / MSIL/Webshell.JS and ghostfile*.aspx), multiple IP-based attack sources were tracked worldwide, IoCs and sample hashes were published, and telemetry indicates both opportunistic cybercriminals and China-aligned APTs (including a LuckyMouse-associated backdoor) leveraged the flaws — Microsoft released patches on July 22 and ESET recommends applying updates, enabling AMSI, and rotating ASP.NET machine keys.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
