picture of zero day exploit on sharepoint

SharePoint Hack: Understanding the Latest Threats

A new wave of cyberattacks is targeting unpatched Microsoft SharePoint servers, with three China-aligned threat actors – Linen Typhoon, Violet Typhoon, and Storm-2603 – now officially linked to the exploitation of recent security flaws. Microsoft confirmed the campaigns in a report released on July 7, 2025, warning that widespread weaponization of these exploits is already underway.

These attacks aren’t speculative – they’re happening now, and they’re succeeding.

How SharePoint Became a Backdoor

The vulnerabilities at the heart of these campaigns affect on-premises SharePoint Server editions and stem from incomplete fixes for two prior bugs: CVE-2025-49706 (spoofing) and CVE-2025-49704 (remote code execution). Attackers have bypassed the original patches using newly assigned CVEs – CVE-2025-53771 and CVE-2025-53770 – via crafted POST requests to the ToolPane endpoint.

These requests allow attackers to bypass authentication and execute malicious code, ultimately enabling them to deploy a backdoor web shell (spinstall0.aspx) that blends into SharePoint’s normal behavior. This web shell exfiltrates sensitive MachineKey data – an access-enabler for deeper compromise.

Researcher Rakesh Krishnan revealed forensic evidence showing Edge browser subprocesses used during the attacks, including the GPU Process and Crashpad Handler, suggesting a calculated strategy to mimic normal browser activity and avoid detection. The attackers also piggyback on Google’s Client Update Protocol to disguise malicious traffic.

The Hackers Behind the Curtain

Microsoft has identified three China-aligned threat groups involved:

  • Linen Typhoon (APT27): Active since 2012, previously linked to PlugX and HyperBro, known for espionage.
  • Violet Typhoon (APT31): A frequent operator in geopolitical campaigns against Western and European targets.
  • Storm-2603: A newer, more aggressive player with a track record of ransomware deployment, including LockBit and Warlock.

This is not an isolated campaign. It follows a familiar pattern seen in 2021, when Silk Typhoon (aka Hafnium) exploited zero-day vulnerabilities in Microsoft Exchange, leading to the infamous ProxyLogon crisis. Earlier this month, Chinese national Xu Zewei was arrested in Italy for his role in that campaign, highlighting the persistent risks posed by Chinese threat actors targeting Microsoft ecosystems.

The Real-World Fallout: Where Enterprises Are Bleeding

These attacks aren’t hypothetical – they’re hitting real targets. Organizations across finance, higher education, and government have already reported breaches that began with the exploitation of SharePoint vulnerabilities. In each case, attackers gained an initial foothold and then moved laterally through internal systems, harvesting credentials, escalating privileges, and establishing long-term persistence, often without triggering any immediate alarms.

What makes these intrusions especially dangerous is how well they blend into normal network activity. Threat actors often exploit legitimate browser processes and mimic standard user behavior, making their actions difficult to distinguish from day-to-day operations. Traditional detection tools may not flag anything unusual. By the time an organization notices unusual behavior or data exfiltration, the damage has already been done – sometimes weeks or months after the initial compromise.

How to Shut It Down: Defenses That Work

Microsoft recommends urgent mitigation steps. Enterprises should:

  • Patch Immediately: Update SharePoint Server Subscription Edition, 2019, and 2016 to close CVE-2025-53770 and CVE-2025-53771.
  • Reset Machine Keys: Rotate ASP.NET machine keys to cut off adversary persistence.
  • Restart IIS: Flush active sessions and apply security configurations.
  • Strengthen Endpoint Defenses: Deploy Microsoft Defender for Endpoint or equivalent EDR/XDR solutions to detect lateral movement and web shell activity.
  • Enable Full AMSI Mode: Use the Antimalware Scan Interface with Defender Antivirus (or similar) in full inspection mode to detect behavioral threats.
  • Limit Exposure: Keep SharePoint behind VPNs or secure access gateways. Internet-facing deployments without strong controls are asking for trouble.

A Pattern of Exploitation – and a Wake-Up Call

The targeting of SharePoint follows a well-established pattern: Chinese APTs identify enterprise-grade Microsoft infrastructure, wait for partial or delayed patches, and move quickly to weaponize them. From Exchange to SharePoint, these systems have become pressure points for espionage, data theft, and disruption.

Enterprises must recognize that patching is no longer optional, and perimeter defenses are not enough. Systems like SharePoint, when left exposed and unmonitored, become high-value attack vectors.

The message is clear: If your Microsoft infrastructure isn’t fully patched and actively defended, it’s not secure.

Now is the time to act – not after the breach.

Need help proactively managing your application updates and security? Get in touch with one of our team today!