Listen to this Post

Microsoft has confirmed that multiple China-linked cyber groups, including Linen Typhoon, Violet Typhoon, and Storm-2603, have been exploiting critical vulnerabilities in SharePoint for initial access since July 7, 2025. This has sparked alarm across the cybersecurity landscape, with Microsoft noting that these groups have targeted unpatched, internet-facing SharePoint servers. The growing concern is that more threat actors are likely to adopt similar tactics, signaling a sharp uptick in cyberattacks aimed at on-premise systems.
the Incident
Microsoft’s recent report has shed light on the tactics, techniques, and procedures (TTPs) used by China-affiliated groups to compromise SharePoint servers. According to the report, these threat actors are leveraging vulnerabilities in the ToolShell component of SharePoint. Their method of attack includes sending POST requests to the ToolPane endpoint of exposed servers. When successful, the attackers bypass authentication, deploying malicious scripts—such as spinstall0.aspx—to steal sensitive cryptographic keys (specifically MachineKey data).
The malicious scripts were designed to fly under the radar, sometimes with slight renaming to evade detection systems. Additionally, the tech giant warns of an increasing number of threat actors adopting these vulnerabilities, suggesting that more attacks on unpatched, on-premise systems are inevitable. To help mitigate these attacks, Microsoft has released a set of Indicators of Compromise (IOCs) and tools for detecting and responding to these threats.
While Microsoft’s report has linked Linen Typhoon, Violet Typhoon, and Storm-2603 to these attacks, SentinelOne’s research reveals that three distinct attack clusters have been identified, each using different tactics. These clusters focused heavily on persistence, aiming for long-term access rather than immediate control of the targeted systems. The attack vectors seem tailored for stealing cryptographic keys, which are of high value to the attackers.
Despite
What Undercode Says:
The increasing sophistication of cyberattacks targeting critical infrastructure, like SharePoint servers, is a cause for major concern. The exploitation of vulnerabilities in such widely used platforms underscores a fundamental issue in global cybersecurity: too many organizations leave their systems exposed to attacks due to poor patch management.
The fact that these China-linked threat groups, which have a long history of cyber espionage, are now exploiting these vulnerabilities is no surprise. Linen Typhoon and Violet Typhoon are known for targeting high-value intellectual property, while Storm-2603’s focus on cryptographic key theft signals a broader, strategic interest in persistent, covert access to systems.
The ongoing battle to secure enterprise platforms like SharePoint shows that cybersecurity isn’t just about defense; it’s also about anticipating the next move. As more threat actors adopt these tactics, organizations must take proactive steps to patch vulnerabilities and strengthen their defenses against targeted cyberattacks. With the rise of nation-state-backed threats, it’s clear that traditional cybersecurity measures may no longer suffice.
While Microsoft’s tools and IOCs can help detect and mitigate these attacks, the ultimate responsibility for defense lies with the system owners themselves. The reality is that many SharePoint servers remain unpatched, exposing sensitive data and cryptographic keys to malicious actors. This creates a dangerous cycle where, despite advanced detection tools, many organizations are still vulnerable to exploitation.
This situation highlights an important trend in modern cyber warfare: persistence over immediate disruption. The attackers aren’t just aiming for a quick hit; they are interested in maintaining a foothold for long-term intelligence gathering. Organizations must be prepared not only for initial breaches but also for ongoing, persistent threats that can evolve over time.
Fact Checker Results:
- Microsoft’s attribution to Linen Typhoon, Violet Typhoon, and Storm-2603 has been confirmed by independent research, though additional clusters are still being analyzed.
- Exploitation of SharePoint vulnerabilities (CVE-2025-53770/53771) is a well-documented threat, with Microsoft and other researchers providing detailed mitigation strategies.
- Ongoing attribution to China-linked actors is based on historical patterns and intelligence gathering, but the evidence remains circumstantial for some threat clusters.
📊 Prediction:
Given the evolving nature of these attacks, it’s likely that more China-linked groups will begin to exploit similar vulnerabilities in widely used enterprise platforms. In addition, organizations that fail to update their systems in a timely manner will become prime targets for future cyberattacks. Moving forward, we may see an increase in cyberattacks aimed not just at disrupting operations but at stealing long-term access credentials, as nation-state actors continue to refine their tactics.
References:
Reported By: securityaffairs.com
Extra Source Hub:
https://stackoverflow.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2




