ATT&CKReferencesMicrosoft SharePoint Exploit JUL 2025

Microsoft SharePoint Exploit JUL 2025

Microsoft Threat Intelligence. (2025, July 22). Disrupting active exploitation of on-premises SharePoint vulnerabilities. Retrieved October 15, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns1

Procedure examples27

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors used Mimikatz to dump LSASS memory.

T1005
Data from Local System
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors extracted information from the compromised systems.

T1027.010
Command Obfuscation
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors executed Base64-encoded PowerShell commands.

T1033
System Owner/User Discovery
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors executed `whoami` on victim machines to enumerate user context and validate privilege levels.

T1041
Exfiltration Over C2 Channel
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors exfiltrated stolen credentials and internal data over HTTPS to C2 infrastructure.

T1047
Windows Management Instrumentation
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors used WMI for execution.

T1053.005
Scheduled Task
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors used scheduled tasks to help establish persistence.

T1059.001
PowerShell
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors used PowerShell to execute attacker-controlled encoded commands.

T1059.003
Windows Command Shell
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors utilized `cmd.exe` and batch scripts within the victim environment.

T1071.001
Web Protocols
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors issued HTTP `POST` requests to web shells with spoofed or empty Referrer headers, to circumvent authorization controls.

T1082
System Information Discovery
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors fingerprinted targeted SharePoint servers to identify OS version and running processes.

T1083
File and Directory Discovery
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors leveraged commands to locate accessible file shares, backup paths, or SharePoint content.

T1090
Proxy
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors used Fast Reverse Proxy to communicate with C2.

T1112
Modify Registry
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors, including Storm-2603, disabled security services via Registry modifications.

T1190
Exploit Public-Facing Application
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors exploited authentication bypass and remote code execution vulnerabilities (CVE-2025-49706 and CVE-2025-49704) against on-premises SharePoint servers. This activity was characterized by crafted `POST` requests to the ToolPane endpoint `/_layouts/15/ToolPane.aspx`.

T1484.001
Group Policy Modification
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors, including Storm-2603, modified group policy to enable ransomware distribution.

T1486
Data Encrypted for Impact
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors deployed ransomware including 4L4MD4R and Warlock.

T1505.003
Web Shell
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors followed exploitation of SharePoint servers with installation of a malicious .aspx web shell (spinstall0.aspx) that was written to the `_layouts/15/` directory, granting persistent HTTP-based access.

T1505.004
IIS Components
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors modified Internet Information Services (IIS) components to load suspicious .NET assemblies for persistence.

T1552.001
Credentials In Files
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors accessed web.config and machine.config to extract MachineKey values, enabling them to forge legitimate VIEWSTATE tokens for future deserialization payloads.

T1569.002
Service Execution
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors leveraged PsExec for command execution and used `services.exe` to disable Microsoft Defender via Registry keys.

T1570
Lateral Tool Transfer
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors used Impacket to remotely stage and execute payloads via WMI.

T1572
Protocol Tunneling
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors utilized ngrok tunnels to deliver PowerShell payloads.

T1583.001
Domains
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors registered C2 domains to spoof legitimate Microsoft domains.

T1588.002
Tool
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors leveraged tools including Impacket, PsExec, and Mimikatz.

T1620
Reflective Code Loading
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors reflectively loaded payloads using `System.Reflection.Assembly.Load`.

T1685
Disable or Modify Tools
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors disabled Microsoft Defender through Registry settings and real-time monitoring via PowerShell.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.