Chinese Threat Actors Exploit ToolShell SharePoint Flaw Weeks After Microsoft’s July Patch

Oct 22, 2025Ravie LakshmananCyber Espionage / Vulnerability

Threat actors with ties to China exploited the ToolShell security vulnerability in Microsoft SharePoint to breach a telecommunications company in the Middle East after it was publicly disclosed and patched in July 2025.

Also targeted were government departments in an African country, as well as government agencies in South America, a university in the U.S., as well as likely a state technology agency in an African country, a government department in the Middle East, and a finance company in a European country.

According to Broadcom’s Symantec Threat Hunter Team, the attacks involved the exploitation of CVE-2025-53770, a now-patched security flaw in on-premise SharePoint servers that could be used to bypass authentication and achieve remote code execution.

DFIR Retainer Services

CVE-2025-53770, assessed to be a patch bypass for CVE-2025-49704 and CVE-2025-49706, has been weaponized as a zero-day by three Chinese threat groups, including Linen Typhoon (aka Budworm), Violet Typhoon (aka Sheathminer), and Storm-2603, the latter of which is linked to the deployment of Warlock, LockBit, and Babuk ransomware families in recent months.

However, the latest findings from Symantec indicate that a much wider range of Chinese threat actors have abused the vulnerability. This includes the Salt Typhoon (aka Glowworm) hacking group, which is said to have leveraged the ToolShell flaw to deploy tools like Zingdoor, ShadowPad, and KrustyLoader against the telecom entity and the two government bodies in Africa.

KrustyLoader, first detailed by Synacktiv in January 2024, is a Rust-based loader previously put to use by a China-nexus espionage group dubbed UNC5221 in attacks exploiting flaws in Ivanti Endpoint Manager Mobile (EPMM) and SAP NetWeaver.

The attacks aimed at government agencies in South America and a university in the U.S., on the other hand, involved the use of unspecified vulnerabilities to obtain initial access, followed by the exploitation of SQL servers and Apache HTTP servers running the Adobe ColdFusion software to deliver the malicious payloads using DLL side-loading techniques.

CIS Build Kits

In some of the incidents, the attackers have been observed executing an exploit for CVE-2021-36942 (aka PetitPotam) for privilege escalation and domain compromise, along with a number of readily available and living-off-the-land (LotL) tools to facilitate scanning, file download, and credential theft on the infected systems.

“There is some overlap in the types of victims and some of the tools used between this activity and activity previously attributed to Glowworm,” Symantec said. “However, we do not have sufficient evidence to conclusively attribute this activity to one specific group, though we can say that all evidence points to those behind it being China-based threat actors.”

“The activity carried out on targeted networks indicates that the attackers were interested in stealing credentials and in establishing persistent and stealthy access to victim networks, likely for the purpose of espionage.”

Source link

Visited 1 times, 1 visit(s) today

Related Article

Anthony Albanese and Donald Trump hold up signed documents in front of flags

The move to break China’s iron grip on world’s supply of critical minerals

If there is any mystery over America’s historic agreement to partner with Australia this week on the supply of critical minerals, it is why it took so long. On April 4, just two days after Donald Trump’s much-touted Liberation Day tariffs panicked investors and sent markets into a tailspin, Beijing retaliated with its own ferocious

Brandi Vincent

As China advances, Congress wants DOD to get up to speed on biotechnology 

Pentagon personnel could soon be told to participate in new training programs designed to prepare them for anticipated advancements in biotechnology and its convergence with other critical and emerging technologies, like quantum computing and AI. House lawmakers recently passed an amendment en bloc in their version of the fiscal 2026 National Defense Authorization Act that

The junta is taking back territory with relentless air strikes and China's help

The junta is taking back territory with relentless air strikes and China’s help

Jonathan HeadSouth East Asia correspondent AFP via Getty Images) When insurgents finally gained control of the town of Kyaukme – on the main trade route from the Chinese border to the rest of Myanmar – it was after several months of hard fighting last year. Kyaukme straddles Asian Highway 14, more famous as the Burma

MSFT, BA, TSLA: U.S. Considers Curbs on Software Exports to China

MSFT, BA, TSLA: U.S. Considers Curbs on Software Exports to China

The administration of U.S. President Donald Trump is reportedly considering placing curbs on software exports to China, including everything from laptop computers to aircraft engines. Elevate Your Investing Strategy: Take advantage of TipRanks Premium at 50% off! Unlock powerful investing tools, advanced data, and expert analyst insights to help you invest with confidence. The curbs

Man stands next to Chinese flag at a podium

Trump seems relaxed about Taiwan and analysts are concerned

For all the celebration of Anthony Albanese’s friendly visit to the White House and the happy news on AUKUS and critical minerals, there was something Donald Trump said that alarmed strategic analysts. And it had nothing to do with disliking Kevin Rudd. The US president’s sunny optimism on China’s intentions towards Taiwan and his confidence

US Stock Market Navigates Record Highs Amidst Government Shutdown and Wealth Surge

The New Iron Curtain: US-China Tech War Escalates with Chip Controls and Rare Earth Weaponization, Reshaping Global AI and Supply Chains

As of October 2025, the geopolitical landscape of technology is undergoing a seismic shift, with the US-China tech war intensifying dramatically. This escalating conflict, primarily centered on advanced semiconductors and critical software, is rapidly forging a bifurcated global technology ecosystem, often dubbed a “digital Cold War.” The immediate significance of these developments is profound, marking

A New US Tech Cocktail: Mixed for China

A New US Tech Cocktail: Mixed for China

The previous Biden administration prioritized strategic industrial planning, export controls, and regulation. The current administration embraces deregulation, private investment, and transactional deal-making. It’s a new cocktail. The current White House prioritizes market-driven growth and deregulation to drive US tech leadership. Biden-era AI risk frameworks have been set aside, cast as “innovation blockers,” and replaced with

US Stock Market Navigates Record Highs Amidst Government Shutdown and Wealth Surge

Micron’s Retreat from China Server Chip Market Signals Deepening US-China Tech Divide

San Francisco, CA – October 22, 2025 – US chipmaker Micron Technology (NASDAQ: MU) is reportedly in the process of ceasing its supply of server chips to Chinese data centers, a strategic withdrawal directly stemming from a 2023 ban imposed by the Chinese government. This move marks a significant escalation in the ongoing technological tensions