Trend Micro Research. (2022, July 22). Proactive Security Insights for SharePoint Attacks (CVE-2025-53770 and CVE-2025-53771). Retrieved October 15, 2025.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.010 Command Obfuscation |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors executed Base64-encoded PowerShell commands. |
| T1071.001 Web Protocols |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors issued HTTP `POST` requests to web shells with spoofed or empty Referrer headers, to circumvent authorization controls. |
| T1074.001 Local Data Staging |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors staged stolen data from web.config files to debug_dev.js. |
| T1119 Automated Collection |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors used a command shell to automatically iterate through web.config files to expose and collect machineKey settings. |
| T1190 Exploit Public-Facing Application |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors exploited authentication bypass and remote code execution vulnerabilities (CVE-2025-49706 and CVE-2025-49704) against on-premises SharePoint servers. This activity was characterized by crafted `POST` requests to the ToolPane endpoint `/_layouts/15/ToolPane.aspx`. |
| T1505.003 Web Shell |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors followed exploitation of SharePoint servers with installation of a malicious .aspx web shell (spinstall0.aspx) that was written to the `_layouts/15/` directory, granting persistent HTTP-based access. |
| T1552.001 Credentials In Files |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors accessed web.config and machine.config to extract MachineKey values, enabling them to forge legitimate VIEWSTATE tokens for future deserialization payloads. |
| T1620 Reflective Code Loading |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors reflectively loaded payloads using `System.Reflection.Assembly.Load`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.