Campaign, Jul 2025 to Jul 2025.View on attack.mitre.org
The SharePoint ToolShell Exploitation campaign was conducted in July 2025 and encompassed the first waves of exploitation against incompletely patched spoofing (CVE-2025-49706) and remote code execution (CVE-2025-49704) vulnerabilities affecting on-premises Microsoft SharePoint servers. Later patched and updated as CVE-2025-53770 and CVE-2025-53771, the ToolShell vulnerabilities were widely exploited including by China-based ransomware actor Storm-2603 and espionage actors Threat Group-3390 and ZIRCONIUM. SharePoint ToolShell Exploitation targeted multiple regions and industries including finance, education, energy, and healthcare across Asia, Europe, and the United States.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
During SharePoint ToolShell Exploitation, threat actors used Mimikatz to dump LSASS memory. |
| T1005 Data from Local System |
During SharePoint ToolShell Exploitation, threat actors extracted information from the compromised systems. |
| T1027.002 Software Packing |
During SharePoint ToolShell Exploitation, threat actors UPX-packed malicous payloads including 4L4MD4R ransomware. |
| T1027.010 Command Obfuscation |
During SharePoint ToolShell Exploitation, threat actors executed Base64-encoded PowerShell commands. |
| T1033 System Owner/User Discovery |
During SharePoint ToolShell Exploitation, threat actors executed `whoami` on victim machines to enumerate user context and validate privilege levels. |
| T1041 Exfiltration Over C2 Channel |
During SharePoint ToolShell Exploitation, threat actors exfiltrated stolen credentials and internal data over HTTPS to C2 infrastructure. |
| T1047 Windows Management Instrumentation |
During SharePoint ToolShell Exploitation, threat actors used WMI for execution. |
| T1053.005 Scheduled Task |
During SharePoint ToolShell Exploitation, threat actors used scheduled tasks to help establish persistence. |
| T1059.001 PowerShell |
During SharePoint ToolShell Exploitation, threat actors used PowerShell to execute attacker-controlled encoded commands. |
| T1059.003 Windows Command Shell |
During SharePoint ToolShell Exploitation, threat actors utilized `cmd.exe` and batch scripts within the victim environment. |
| T1071.001 Web Protocols |
During SharePoint ToolShell Exploitation, threat actors issued HTTP `POST` requests to web shells with spoofed or empty Referrer headers, to circumvent authorization controls. |
| T1074.001 Local Data Staging |
During SharePoint ToolShell Exploitation, threat actors staged stolen data from web.config files to debug_dev.js. |
| T1082 System Information Discovery |
During SharePoint ToolShell Exploitation, threat actors fingerprinted targeted SharePoint servers to identify OS version and running processes. |
| T1083 File and Directory Discovery |
During SharePoint ToolShell Exploitation, threat actors leveraged commands to locate accessible file shares, backup paths, or SharePoint content. |
| T1090 Proxy |
During SharePoint ToolShell Exploitation, threat actors used Fast Reverse Proxy to communicate with C2. |
MITRE does not attribute this campaign to a group.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.