Eye Security. (2025, July 19). SharePoint Under Siege: ToolShell Exploit (CVE-2025-49706 & CVE-2025-49704). Retrieved October 15, 2025.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.010 Command Obfuscation |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors executed Base64-encoded PowerShell commands. |
| T1059.001 PowerShell |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors used PowerShell to execute attacker-controlled encoded commands. |
| T1059.003 Windows Command Shell |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors utilized `cmd.exe` and batch scripts within the victim environment. |
| T1071.001 Web Protocols |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors issued HTTP `POST` requests to web shells with spoofed or empty Referrer headers, to circumvent authorization controls. |
| T1190 Exploit Public-Facing Application |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors exploited authentication bypass and remote code execution vulnerabilities (CVE-2025-49706 and CVE-2025-49704) against on-premises SharePoint servers. This activity was characterized by crafted `POST` requests to the ToolPane endpoint `/_layouts/15/ToolPane.aspx`. |
| T1505.003 Web Shell |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors followed exploitation of SharePoint servers with installation of a malicious .aspx web shell (spinstall0.aspx) that was written to the `_layouts/15/` directory, granting persistent HTTP-based access. |
| T1552.001 Credentials In Files |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors accessed web.config and machine.config to extract MachineKey values, enabling them to forge legitimate VIEWSTATE tokens for future deserialization payloads. |
| T1620 Reflective Code Loading |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors reflectively loaded payloads using `System.Reflection.Assembly.Load`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.