logo

Sharepoint ToolShell attacks targeted orgs across four continents

ID: 4b295f1e-61bb-5467-96ab-f970d9c84963

STIX ID: report--4b295f1e-61bb-5467-96ab-f970d9c84963

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2025-10-22

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

Symantec reports that the ToolShell SharePoint zero-day (CVE-2025-53770) has been actively exploited by Chinese-linked threat groups to compromise government, telecom, finance, and academic organizations worldwide; attackers used webshells and DLL side‑loading to deploy Zingdoor, ShadowPad, KrustyLoader, and the Sliver framework, and performed credential dumping and PetitPotam-based domain compromise, while Microsoft released emergency updates to address the on‑premises SharePoint flaw.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.