Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Yes 5G Advanced Field Test: An exciting yet frustrating experience

    Sony A7 V leak points to underwhelming next-gen full-frame camera launch, with lacklustre video features on the cards

    Stable HyperOS 3 rolls out to Xiaomi Pad 7, with more Xiaomi and Redmi devices to follow later this month

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      Amazon to lay off 14,000 corporate employees

      October 29, 2025

      Elon Musk launches Grokipedia as an alternative to ‘woke’ Wikipedia

      October 29, 2025

      Fears of an AI bubble are growing, but some on Wall Street aren’t worried just yet

      October 18, 2025

      The sleeper issue that could play a huge role in Virginia and New Jersey — and the midterms

      October 16, 2025

      California bill regulating top AI companies signed into law

      September 30, 2025
    • Business

      Government faces questions about why US AWS outage disrupted UK tax office and banking firms

      October 23, 2025

      Amazon’s AWS outage knocked services like Alexa, Snapchat, Fortnite, Venmo and more offline

      October 21, 2025

      SAP ECC customers bet on composable ERP to avoid upgrading

      October 18, 2025

      Revenue generated by neoclouds expected to exceed $23bn in 2025, predicts Synergy

      October 15, 2025

      You can now try Fortnite directly in Discord

      October 8, 2025
    • Crypto

      JPMorgan Achieves First True Bridge Between Banks and DeFi

      November 12, 2025

      3 Signs Pointing to Mounting Selling Pressure on Pi Network in November

      November 12, 2025

      Dogecoin Faces Its Toughest Q4 In Years — Can a Late Bounce Save 2025?

      November 12, 2025

      Did One Whale Steal aPriori’s Airdrop? 14,000 Wallets Raise Big Questions

      November 12, 2025

      Why Analysts See A $5 Target for XRP Price in Q4 2025

      November 12, 2025
    • Technology

      Sony A7 V leak points to underwhelming next-gen full-frame camera launch, with lacklustre video features on the cards

      November 12, 2025

      Stable HyperOS 3 rolls out to Xiaomi Pad 7, with more Xiaomi and Redmi devices to follow later this month

      November 12, 2025

      Stable HyperOS 3 for Xiaomi Pad 7

      November 12, 2025

      Suunto adds two new running metrics to smartwatches in update

      November 12, 2025

      Sora 2 is OpenAI’s consistently inconsistent AI video creator

      November 12, 2025
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Technology»Sharepoint ToolShell attacks targeted orgs across four continents
    Technology

    Sharepoint ToolShell attacks targeted orgs across four continents

    TechAiVerseBy TechAiVerseOctober 22, 2025No Comments3 Mins Read0 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    Sharepoint ToolShell attacks targeted orgs across four continents
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    Sharepoint ToolShell attacks targeted orgs across four continents

    Hackers believed to be associated with China have leveraged the ToolShell vulnerability (CVE-2025-53770) in Microsoft SharePoint in attacks targeting government agencies, universities, telecommunication service providers, and finance organizations.

    The security flaw affects on-premise SharePoint servers and was disclosed as an actively exploited zero-day on July 20, after multiple hacking groups tied to China leveraged it in widespread attacks. Microsoft released emergency updates the following day.

    The issue is a bypass for CVE-2025-49706 and CVE-2025-49704, two flaws that Viettel Cyber Security researchers had demonstrated at the Pwn2Own Berlin hacking competition in May, and can be leveraged remotely without authentication for code execution and full access to the file system.

    Microsoft previously said that ToolShell was exploited by three Chinese threat groups, Budworm/Linen Typhoon, Sheathminer/Violet Typhoon, and Storm-2603/Warlock ransomware.

    In a report today, cybersecurity company Symantec, part of Broadcom, says that ToolShell was used to compromise various organizations in the Middle East, South America, the U.S., and Africa, and the campaigns leveraged malware typically associated with the Salt Typhoon Chinese hackers:

    • A telecommunications service provider in the Middle East
    • Two government departments in an African country
    • Two government agencies in South America
    • A university in the United States
    • A state technology agency in Africa
    • A Middle Eastern government department
    • A European finance company

    The activity on the telecommunications firm, which is the focus of Symantec’s report, started on July 21 with CVE-2025-53770 being exploited to plant webshells that enable persistent access.

    This was followed by DLL side-loading a Go-based backdoor named Zingdoor, which can collect system info, perform file operations, and also facilitate remote command execution.

    Then, another side-loading step launched “what appears to be the ShadowPad Trojan,” the researchers said, adding that the action was followed by dropping the Rust-based KrustyLoader tool, which eventually deployed the Sliver open-source post-exploitation framework.

    Notably, the side-loading steps were conducted using legitimate Trend Micro and BitDefender executables. For the attacks in South America, the threat actors used a file resembling Symantec’s name.

    Next, the attackers proceeded to perform credential dumping via ProcDump, Minidump, and LsassDumper, and leveraged PetitPotam (CVE-2021-36942) for domain compromise.

    The researchers note that the list of publicly available and living-off-the-land tools used in the attacks included Certutil utility from Microsoft, the GoGo Scanner (a red-team scanning engine), and the Revsocks utility that allows data exfiltration, command-and-control, and persistence on the compromised device.

    Symantec says that its findings indicate that the ToolShell vulnerability was exploited by a larger set of Chinese threat actors than was previously known.

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleVidar Stealer 2.0 adds multi-threaded data theft, better evasion
    Next Article Biodiversity: A missing link in combating climate change
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    Sony A7 V leak points to underwhelming next-gen full-frame camera launch, with lacklustre video features on the cards

    November 12, 2025

    Stable HyperOS 3 rolls out to Xiaomi Pad 7, with more Xiaomi and Redmi devices to follow later this month

    November 12, 2025

    Stable HyperOS 3 for Xiaomi Pad 7

    November 12, 2025
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 2025378 Views

    Lumo vs. Duck AI: Which AI is Better for Your Privacy?

    July 31, 202597 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 202571 Views

    Is Libby Compatible With Kobo E-Readers?

    March 31, 202555 Views
    Don't Miss
    Gadgets November 13, 2025

    Yes 5G Advanced Field Test: An exciting yet frustrating experience

    Yes 5G Advanced Field Test: An exciting yet frustrating experience Since the WiMAX days, Yes…

    Sony A7 V leak points to underwhelming next-gen full-frame camera launch, with lacklustre video features on the cards

    Stable HyperOS 3 rolls out to Xiaomi Pad 7, with more Xiaomi and Redmi devices to follow later this month

    Stable HyperOS 3 for Xiaomi Pad 7

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    Yes 5G Advanced Field Test: An exciting yet frustrating experience

    November 13, 20253 Views

    Sony A7 V leak points to underwhelming next-gen full-frame camera launch, with lacklustre video features on the cards

    November 12, 20253 Views

    Stable HyperOS 3 rolls out to Xiaomi Pad 7, with more Xiaomi and Redmi devices to follow later this month

    November 12, 20251 Views
    Most Popular

    Xiaomi 15 Ultra Officially Launched in China, Malaysia launch to follow after global event

    March 12, 20250 Views

    Apple thinks people won’t use MagSafe on iPhone 16e

    March 12, 20250 Views

    French Apex Legends voice cast refuses contracts over “unacceptable” AI clause

    March 12, 20250 Views
    © 2025 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.