Sharepoint ToolShell attacks targeted orgs across four continents
ID: 4b295f1e-61bb-5467-96ab-f970d9c84963
STIX ID: report--4b295f1e-61bb-5467-96ab-f970d9c84963
Feed Name: Bleeping Computer
Symantec reports that the ToolShell SharePoint zero-day (CVE-2025-53770) has been actively exploited by Chinese-linked threat groups to compromise government, telecom, finance, and academic organizations worldwide; attackers used webshells and DLL side‑loading to deploy Zingdoor, ShadowPad, KrustyLoader, and the Sliver framework, and performed credential dumping and PetitPotam-based domain compromise, while Microsoft released emergency updates to address the on‑premises SharePoint flaw.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
