ATT&CKCampaignsSharePoint ToolShell Exploitation

SharePoint ToolShell Exploitation

C0058

Campaign, Jul 2025 to Jul 2025.View on attack.mitre.org

About this campaign

The SharePoint ToolShell Exploitation campaign was conducted in July 2025 and encompassed the first waves of exploitation against incompletely patched spoofing (CVE-2025-49706) and remote code execution (CVE-2025-49704) vulnerabilities affecting on-premises Microsoft SharePoint servers. Later patched and updated as CVE-2025-53770 and CVE-2025-53771, the ToolShell vulnerabilities were widely exploited including by China-based ransomware actor Storm-2603 and espionage actors Threat Group-3390 and ZIRCONIUM. SharePoint ToolShell Exploitation targeted multiple regions and industries including finance, education, energy, and healthcare across Asia, Europe, and the United States.

Techniques used35

Procedure examples35

TechniqueProcedure example
T1003.001
LSASS Memory

During SharePoint ToolShell Exploitation, threat actors used Mimikatz to dump LSASS memory.

T1005
Data from Local System

During SharePoint ToolShell Exploitation, threat actors extracted information from the compromised systems.

T1027.002
Software Packing

During SharePoint ToolShell Exploitation, threat actors UPX-packed malicous payloads including 4L4MD4R ransomware.

T1027.010
Command Obfuscation

During SharePoint ToolShell Exploitation, threat actors executed Base64-encoded PowerShell commands.

T1033
System Owner/User Discovery

During SharePoint ToolShell Exploitation, threat actors executed `whoami` on victim machines to enumerate user context and validate privilege levels.

T1041
Exfiltration Over C2 Channel

During SharePoint ToolShell Exploitation, threat actors exfiltrated stolen credentials and internal data over HTTPS to C2 infrastructure.

T1047
Windows Management Instrumentation

During SharePoint ToolShell Exploitation, threat actors used WMI for execution.

T1053.005
Scheduled Task

During SharePoint ToolShell Exploitation, threat actors used scheduled tasks to help establish persistence.

T1059.001
PowerShell

During SharePoint ToolShell Exploitation, threat actors used PowerShell to execute attacker-controlled encoded commands.

T1059.003
Windows Command Shell

During SharePoint ToolShell Exploitation, threat actors utilized `cmd.exe` and batch scripts within the victim environment.

T1071.001
Web Protocols

During SharePoint ToolShell Exploitation, threat actors issued HTTP `POST` requests to web shells with spoofed or empty Referrer headers, to circumvent authorization controls.

T1074.001
Local Data Staging

During SharePoint ToolShell Exploitation, threat actors staged stolen data from web.config files to debug_dev.js.

T1082
System Information Discovery

During SharePoint ToolShell Exploitation, threat actors fingerprinted targeted SharePoint servers to identify OS version and running processes.

T1083
File and Directory Discovery

During SharePoint ToolShell Exploitation, threat actors leveraged commands to locate accessible file shares, backup paths, or SharePoint content.

T1090
Proxy

During SharePoint ToolShell Exploitation, threat actors used Fast Reverse Proxy to communicate with C2.

View all 35 procedure examples

Attributed groups0

MITRE does not attribute this campaign to a group.

Software4

References5

  1. ESET ToolShell JUL 2025 Open source
    ESET Research. (2025, July 24). ToolShell: An all-you-can-eat buffet for threat actors. Retrieved October 15, 2025.
  2. Eye Research ToolShell JUL 2025 Open source
    Eye Security. (2025, July 19). SharePoint Under Siege: ToolShell Exploit (CVE-2025-49706 & CVE-2025-49704). Retrieved October 15, 2025.
  3. Microsoft SharePoint Exploit JUL 2025 Open source
    Microsoft Threat Intelligence. (2025, July 22). Disrupting active exploitation of on-premises SharePoint vulnerabilities. Retrieved October 15, 2025.
  4. Palo Alto SharePoint Vulnerabilities JUL 2025 Open source
    Unit 42. (2025, July 31). Active Exploitation of Microsoft SharePoint Vulnerabilities: Threat Brief (Updated). Retrieved October 15, 2025.
  5. Trend Micro SharePoint Attacks JUL 2025 Open source
    Trend Micro Research. (2022, July 22). Proactive Security Insights for SharePoint Attacks (CVE-2025-53770 and CVE-2025-53771). Retrieved October 15, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.