New ToolShell Cyberattack Targets Microsoft SharePoint with Dual Zero-Day Exploits

Listen to this Post

Featured Image

A Dangerous Threat Lurking in Your SharePoint Servers

A new cyberattack campaign dubbed ToolShell has been uncovered by FortiGuard Labs, and it’s sending shockwaves through the enterprise cybersecurity community. The attack focuses on on-premises Microsoft SharePoint servers, using both old vulnerabilities and new zero-day exploits to take full control of vulnerable systems. With backing from the U.S. Cybersecurity and Infrastructure Security Agency (CISA), which added these to its Known Exploited Vulnerabilities (KEV) list, it’s clear this threat is not theoretical — it’s active and dangerous.

ToolShell doesn’t just use one method. It combines a multi-stage reconnaissance, advanced malware payloads, and stealthy evasion techniques to dig deep into organizational networks. From information gathering using simple curl and PowerShell commands, to post-exploitation malware like GhostWebShell and KeySiphon, the attackers behind this campaign are both well-resourced and highly methodical. Enterprises running SharePoint 2016, 2019, or the Subscription Edition must take immediate action. With tools like cmd.exe remote shell spawning, credential theft, and even token forgery via system-level APIs, ToolShell is a full-spectrum attack that leaves no stone unturned.

Let’s break down what’s happening, what’s at risk, and how organizations can stay protected.

ToolShell: A Sophisticated Multi-Layered Cyber Assault

The ToolShell campaign marks a turning point in how attackers exploit enterprise systems. Leveraging two known vulnerabilities — CVE-2025-49704 and CVE-2025-49706 — alongside two fresh zero-days — CVE-2025-53770 and CVE-2025-53771 — the threat actors gain remote code execution (RCE) on vulnerable Microsoft SharePoint servers. Attacks begin via a compromised spinstall0.aspx endpoint, where simple curl commands or PowerShell scripts collect internal system data. Commands like ipconfig and Get-WmiObject are used to build a detailed map of the victim’s infrastructure.

Once the layout is understood, the attackers launch malware payloads. GhostWebShell acts as a fileless backdoor. It accepts ?cmd= inputs from attackers, executes commands on the fly, and sends output back in a web-friendly format. Meanwhile, KeySiphon harvests credentials and system metadata. One of its more alarming features is its ability to call private methods within SharePoint’s backend, stealing validation and decryption keys, which could let attackers forge authentication tokens and manipulate session state.

The evasion tactics are no less sophisticated. Both malware variants use reflective methods to bypass SharePoint’s normal compilation checks. By manipulating .NET components like VirtualPathProvider and BuildManager, they fly under the radar of many traditional security tools. Fortinet has already rolled out updated intrusion prevention system (IPS) signatures and antivirus definitions. Still, this attack is fast-moving, and security teams must act now.

Indicators of compromise include several known malicious IP addresses and file hashes, as well as unusual traffic in the /_layouts/15/ directory — often involving dynamically named .aspx files. Monitoring for these patterns, combined with patching and behavioral detection, remains critical. As attackers grow bolder and toolkits more advanced, this campaign serves as a wake-up call to any enterprise still lagging behind in cybersecurity hygiene.

What Undercode Say:

The Rise of Enterprise-Targeted Zero-Day Campaigns

The ToolShell campaign is more than just a new exploit — it’s an indicator of where enterprise threat landscapes are headed. What makes this campaign especially concerning is its hybrid nature. By blending patched vulnerabilities with brand-new zero-days, attackers are maximizing their chances of success, especially in environments where patch management is inconsistent. This dual-exploit technique shows a clear evolution in attacker methodology. Rather than relying on brute force or phishing, they’re targeting specific, high-value platforms like SharePoint.

Advanced Malware Behaviors Bypass Traditional Defenses

GhostWebShell’s fileless nature and base64 encoding represent a strategic shift in how malware is deployed in enterprise settings. It leaves no traditional file footprints, making it invisible to signature-based antivirus solutions. KeySiphon’s ability to interact with private API methods — like MachineKeySection.GetApplicationConfig — goes beyond basic credential theft. It opens the door to session hijacking, forged user identities, and even customized payload deployment.

Exploitation of Microsoft-Specific Architecture

This campaign also reveals the fragility of complex enterprise platforms like SharePoint. Attackers are clearly reverse-engineering Microsoft’s .NET architecture, exploiting the VirtualPathProvider to inject arbitrary paths and content into runtime environments. These subtle but powerful manipulations allow them to load and execute code without alerting most defensive systems. The implications are severe: once attackers have the keys to the kingdom, lateral movement inside networks becomes trivial.

Defensive Gaps in Visibility and Response

While Fortinet has released IPS and AV signatures, many organizations still rely on outdated or siloed defense tools. For example, without log aggregation tools or SIEMs that correlate behavioral anomalies, many ToolShell indicators — like sudden POST requests to spinstall0.aspx — may go unnoticed. Enterprise defense strategies must evolve to include behavioral analysis, zero trust architecture, and network segmentation, especially for core services like SharePoint.

The Urgent Need for Patch Discipline

Organizations often delay patching due to compatibility testing or resource constraints. But with attackers now combining N-day and 0-day tactics in real time, the risk is exponentially higher. The inclusion of these CVEs in CISA’s KEV catalog underscores how quickly critical vulnerabilities are being exploited once publicized. Enterprises must treat every delay in patching as a potential attack window.

A Call to Action: Multi-Layered Security Is No Longer Optional

ToolShell isn’t just an attack — it’s a methodology. It shows how today’s attackers blend reconnaissance, privilege escalation, and stealthy post-exploitation with surgical precision. No single security product can defend against this on its own. Organizations must invest in endpoint detection and response (EDR), threat hunting, automated patch management, and staff training. Only a comprehensive, proactive approach will close the gap.

🔍 Fact Checker Results:

✅ Confirmed: ToolShell uses four distinct CVEs, two of which are brand-new zero-day vulnerabilities.
✅ Verified: GhostWebShell and KeySiphon are real malware strains analyzed by FortiGuard Labs.
✅ Supported: CISA has listed the vulnerabilities in its Known Exploited Vulnerabilities catalog.

📊 Prediction:

The ToolShell campaign is just the beginning. Over the next 12 months, we’re likely to see a wave of similar attacks targeting other Microsoft enterprise platforms like Exchange, SQL Server, and Dynamics. Attackers have realized that enterprise applications offer deep system access, and vendors are often slow to patch. Expect growing use of modular malware, zero-day stockpiling, and living-off-the-land (LOTL) techniques in these environments. Enterprises that don’t adopt real-time monitoring and agile patching protocols will face an increasing risk of full domain compromise. 🔐💥

References:

Reported By: cyberpress.org
Extra Source Hub:
https://www.reddit.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon