Listen to this Post

Introduction
In a major escalation of cyberattacks, hackers reportedly linked to China have exploited a critical Microsoft SharePoint vulnerability, CVE-2025-53770, known as ToolShell. The attacks have targeted government agencies, universities, telecommunications firms, and financial institutions across multiple continents, raising alarm about the sophistication and global reach of these campaigns. Microsoft issued emergency patches immediately after the flaw was publicly disclosed, but the speed and scale of the attacks demonstrate how quickly threat actors can weaponize zero-day vulnerabilities.
Summary of the Attacks
Hackers exploited the ToolShell vulnerability on on-premise SharePoint servers, which bypasses two previously reported vulnerabilities, CVE-2025-49706 and CVE-2025-49704. Researchers from Viettel Cyber Security had first demonstrated these weaknesses at the Pwn2Own Berlin hacking competition in May, highlighting their potential for remote code execution and full file system access without authentication.
Microsoft confirmed that three Chinese-linked groups—Budworm/Linen Typhoon, Sheathminer/Violet Typhoon, and Storm-2603/Warlock ransomware—actively exploited ToolShell. Symantec (Broadcom) reports that attacks spanned the Middle East, South America, the U.S., Africa, and Europe, targeting:
A Middle Eastern telecommunications provider
Two African government departments
Two South American government agencies
A U.S. university
An African state technology agency
A Middle Eastern government department
A European finance company
The attacks on the telecommunications firm began on July 21, leveraging CVE-2025-53770 to plant persistent webshells. Following this, the threat actors deployed a Go-based backdoor, Zingdoor, which collected system data, executed files, and allowed remote command execution. Subsequently, ShadowPad Trojan activity was observed, and the Rust-based KrustyLoader was used to deploy the Sliver open-source post-exploitation framework.
Notably, the hackers conducted side-loading using legitimate Trend Micro and BitDefender executables, demonstrating a sophisticated ability to blend malicious actions with trusted software. In South America, attackers even used files resembling Symantec’s branding to evade detection.
The campaign progressed with credential dumping via ProcDump, Minidump, and LsassDumper and leveraged PetitPotam (CVE-2021-36942) for domain compromise. Other publicly available tools used included Microsoft’s Certutil, the GoGo Scanner red-team engine, and Revsocks for data exfiltration and persistence. Symantec’s findings suggest that a larger set of Chinese threat actors exploited ToolShell than initially understood.
What Undercode Say:
The ToolShell exploitation highlights an alarming trend in global cybersecurity threats: the convergence of zero-day vulnerabilities, sophisticated malware chains, and the strategic targeting of critical infrastructure. The use of multiple side-loading stages, legitimate executables, and living-off-the-land tools demonstrates a highly calculated approach to evading detection. By mimicking trusted software and leveraging open-source frameworks like Sliver, attackers extend their dwell time, maximizing damage before detection.
This campaign also underscores the importance of rapid patch management. Microsoft released updates within a day of the zero-day disclosure, but the sheer speed of exploitation shows that even immediate patching may not be enough if organizations lack proactive threat monitoring and anomaly detection.
The targeting pattern reflects a strategic choice: governments, finance, universities, and telecoms represent high-value data repositories and operational criticality. Attackers likely aim not only at data theft but also at building persistent footholds for future operations, potentially disrupting services or gaining leverage in geopolitical conflicts.
Credential dumping and domain compromise indicate that these threat actors are not content with surface-level intrusions. Tools like PetitPotam allow attackers to elevate privileges and move laterally across networks, turning a single SharePoint compromise into a full domain-level infiltration.
Moreover, the variety of malware used—Zingdoor, ShadowPad, KrustyLoader, and Sliver—reveals a modular, flexible attack methodology. The combination of Go, Rust, and widely-used Windows tools suggests attackers are optimizing for speed, versatility, and evasion. Such techniques highlight the increasing sophistication of state-sponsored cyber operations, which can now execute globally coordinated campaigns with minimal friction.
Another point worth noting is the psychological aspect of mimicry. Using files resembling Symantec or legitimate security software plays on the trust organizations place in familiar brands, reducing the likelihood of immediate detection. This emphasizes the need for continuous security awareness training alongside technical defenses.
Finally, Symantec’s observation that more Chinese groups were involved than previously known suggests an expanding ecosystem of state-aligned threat actors. This implies that cybersecurity strategies must evolve from reactive defense toward predictive intelligence, monitoring geopolitical trends and threat actor behaviors.
Fact Checker Results
✅ CVE-2025-53770 (ToolShell) is a verified SharePoint vulnerability exploited in the wild.
✅ Multiple Chinese-linked hacking groups leveraged the flaw across global targets.
❌ There is no evidence the attacks resulted in catastrophic service outages; impacts were primarily data compromise and persistence.
Prediction
📊 Expect increased global surveillance and patching activity around Microsoft SharePoint and related systems, as organizations anticipate further zero-day exploitation.
📊 Industries such as telecommunications, finance, and government will likely invest more in endpoint detection and response tools capable of spotting side-loading and living-off-the-land attacks.
📊 Chinese threat actors may expand their campaigns into more regions, adopting increasingly sophisticated evasion techniques, potentially making multinational organizations the primary targets for strategic cyber operations.
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: www.bleepingcomputer.com
Extra Source Hub (Possible Sources for article):
https://www.linkedin.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
Bing
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




