Chinese Threat Actors Exploit ToolShell SharePoint Flaw Weeks After Microsoft’s July Patch

Oct 22, 2025Ravie LakshmananCyber Espionage / Vulnerability

Threat actors with ties to China exploited the ToolShell security vulnerability in Microsoft SharePoint to breach a telecommunications company in the Middle East after it was publicly disclosed and patched in July 2025.

Also targeted were government departments in an African country, as well as government agencies in South America, a university in the U.S., as well as likely a state technology agency in an African country, a government department in the Middle East, and a finance company in a European country.

According to Broadcom’s Symantec Threat Hunter Team, the attacks involved the exploitation of CVE-2025-53770, a now-patched security flaw in on-premise SharePoint servers that could be used to bypass authentication and achieve remote code execution.

DFIR Retainer Services

CVE-2025-53770, assessed to be a patch bypass for CVE-2025-49704 and CVE-2025-49706, has been weaponized as a zero-day by three Chinese threat groups, including Linen Typhoon (aka Budworm), Violet Typhoon (aka Sheathminer), and Storm-2603, the latter of which is linked to the deployment of Warlock, LockBit, and Babuk ransomware families in recent months.

However, the latest findings from Symantec indicate that a much wider range of Chinese threat actors have abused the vulnerability. This includes the Salt Typhoon (aka Glowworm) hacking group, which is said to have leveraged the ToolShell flaw to deploy tools like Zingdoor, ShadowPad, and KrustyLoader against the telecom entity and the two government bodies in Africa.

KrustyLoader, first detailed by Synacktiv in January 2024, is a Rust-based loader previously put to use by a China-nexus espionage group dubbed UNC5221 in attacks exploiting flaws in Ivanti Endpoint Manager Mobile (EPMM) and SAP NetWeaver.

The attacks aimed at government agencies in South America and a university in the U.S., on the other hand, involved the use of unspecified vulnerabilities to obtain initial access, followed by the exploitation of SQL servers and Apache HTTP servers running the Adobe ColdFusion software to deliver the malicious payloads using DLL side-loading techniques.

CIS Build Kits

In some of the incidents, the attackers have been observed executing an exploit for CVE-2021-36942 (aka PetitPotam) for privilege escalation and domain compromise, along with a number of readily available and living-off-the-land (LotL) tools to facilitate scanning, file download, and credential theft on the infected systems.

“There is some overlap in the types of victims and some of the tools used between this activity and activity previously attributed to Glowworm,” Symantec said. “However, we do not have sufficient evidence to conclusively attribute this activity to one specific group, though we can say that all evidence points to those behind it being China-based threat actors.”

“The activity carried out on targeted networks indicates that the attackers were interested in stealing credentials and in establishing persistent and stealthy access to victim networks, likely for the purpose of espionage.”

Source link

Visited 1 times, 1 visit(s) today

Related Article

US Stock Market Navigates Record Highs Amidst Government Shutdown and Wealth Surge

Micron’s Retreat from China Server Chip Market Signals Deepening US-China Tech Divide

San Francisco, CA – October 22, 2025 – US chipmaker Micron Technology (NASDAQ: MU) is reportedly in the process of ceasing its supply of server chips to Chinese data centers, a strategic withdrawal directly stemming from a 2023 ban imposed by the Chinese government. This move marks a significant escalation in the ongoing technological tensions

Dismissing China’s technological potential would be a big mistake

Dismissing China’s technological potential would be a big mistake

In the corridors of Western think tanks and financial institutions, a familiar refrain has grown louder: China’s economy is stumbling, its growth model is exhausted, and its technological ambitions are overreaching. Yet while skeptics sharpen their prophecies of doom, something consequential is unfolding across the Pearl River Delta — a transformation that suggests the doomsayers

[Latest] China Oil And Gas Market Strategic Importance

[Latest] China Oil And Gas Market Strategic Importance

China Oil And Gas Market Outlook & Investment Analysis Q1: What is the current outlook for the China Oil and Gas Market? The China Oil and Gas Market remains one of the fastest-growing sectors globally, driven by the country’s expanding industrial base and urbanization. Despite global shifts towards renewable energy, China’s demand for oil and

ET logo

Trump China 155% tariff market crash prediction: Trump puts China on notice with 155% tariff threat – is a November market crash coming?

President Donald Trump has once again sent shockwaves through global markets by threatening to impose a 155% tariff on Chinese imports starting November 1, 2025. The announcement has sparked intense debate across Wall Street, Beijing, and beyond, raising fears of a potential market crash just weeks before the year’s end. In a fiery statement from

General Views of Beijing Ahead of China Plenum

China Leadership Meeting To Highlight Tech Goals: DGA’s Ken Jarrett

Visitors salutes in front of a portrait of former Chinese leader Mao Zedong at Tiananmen Square in Beijing. Communist Party leaders have gathered for a plenum in the city Oct. 20-23. Photographer: Na Bian/Bloomberg © 2024 Bloomberg Finance LP A gathering of more than 200 top leaders of China’s Communist Party in Beijing this week

Protesters march in Minneapolis, Minnesota, on Saturday. Organisers estimated that more than seven million people marched in the ‘No Kings’ rallies held from New York to Los Angeles. Photo: TNS

Chinese state media says US ‘dying from within’ as Beijing drafts next 5-year plan

Chinese state media has labelled the US a failed state, claiming it is “dying from within” as its global hegemony declines. The commentary published in Beijing Daily on Tuesday came as China’s policymakers prepared to outline long-term plans amid intensifying competition with Washington. Beijing on Monday began a key four-day conclave that will determine the

Canadians’ view of China improves in response to U.S. tariffs

Canadians’ view of China improves in response to U.S. tariffs

Source: Wikimedia Commons Canadians’ views on trade with China have shifted following U.S. tariffs, with many wanting Ottawa to prioritize economic common ground with Beijing. A survey conducted last week by the Angus Reid Institute, in partnership with the Asia Pacific Foundation of Canada, found that 27 per cent of Canadians now hold a favourable

Google Preferred Source

China wants US semiconductor companies to submit sensitive data as part of probe — ‘anti-dumping’ investigation requests sales and profit data

China has launched a raft of new questionnaires for US semiconductor businesses in an effort to discover data on the companies’ activities in China, and particularly how their prices, income, and profits differ between native US sales and those in Asian territories, like China, via Bloomberg. Although no companies have been named specifically, the wording