Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
state-sponsored-espionageactively-exploited-vulnerabilitygovernment-diplomatic-threattelecommunications-sector-threat

China-Linked Hackers Exploit SharePoint ToolShell Flaws to Breach Governments and Telecoms

Updated 28d agoFirst seen May 25, 20265 sources

Microsoft disclosed multiple on-premises SharePoint Server vulnerabilities, including remote code execution flaws CVE-2025-49701 and CVE-2025-49704 and spoofing flaw CVE-2025-49706, as defenders responded to active exploitation. Microsoft said it was working to disrupt attacks targeting exposed SharePoint environments, while the Canadian Centre for Cyber Security issued threat-detection guidance to help organizations identify compromise tied to the SharePoint vulnerabilities.

Subsequent reporting tied the broader ToolShell exploitation chain, including CVE-2025-53770, to China-linked operators that breached a Middle Eastern telecom provider, government departments in Africa, government agencies in South America, and a U.S. university. Investigators said the intrusions used malware and tooling including Zingdoor, ShadowPad, KrustyLoader, and Sliver, alongside credential-dumping, proxying, DLL sideloading, and persistence techniques, indicating a stealthy espionage-focused campaign that expanded beyond initial public understanding of the SharePoint attacks.

Share:
China-Linked Hackers Exploit SharePoint ToolShell Flaws to Breach Governments and Telecoms
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Oct 22, 20258mo ago

Symantec links ToolShell intrusions to broader China-linked espionage activity

Symantec reported that ToolShell exploitation had compromised a Middle Eastern telecom, two African government departments, two South American government agencies, and a U.S. university, with likely additional victims in Africa, the Middle East, and Europe. The report also described tooling including Zingdoor, ShadowPad, KrustyLoader, Sliver, and credential-dumping utilities, and assessed the operators as China-based actors engaged in likely espionage.

Aug 28, 202510mo ago

Canadian Centre for Cyber Security issues SharePoint threat detection guidance

The Canadian Centre for Cyber Security published threat detection guidance related to SharePoint vulnerabilities. This reflects official defensive guidance for organizations monitoring for related exploitation activity.

Jul 22, 202511mo ago

Microsoft details active exploitation of on-premises SharePoint vulnerabilities

Microsoft published a security blog on disrupting active exploitation of on-premises SharePoint vulnerabilities. The post signaled that exploitation was ongoing and outlined Microsoft's response to the campaign.

Jul 21, 202511mo ago

Mandiant says a China-based threat actor is involved in SharePoint attacks

CRN reported Mandiant's assessment that a China-based threat actor was involved in the Microsoft SharePoint attack activity. This represented an early public attribution update tying the exploitation to China-linked operators.

Jul 8, 20251y ago

Attackers begin exploiting ToolShell shortly after July patches

According to later Symantec reporting, China-linked attackers exploited the ToolShell SharePoint vulnerability CVE-2025-53770 soon after Microsoft patched SharePoint in July 2025. Early victims included a telecom company in the Middle East and government entities in Africa, indicating rapid post-patch operational use.

Microsoft publishes SharePoint fixes for CVE-2025-49701, CVE-2025-49704, and CVE-2025-49706

Microsoft released Security Update Guide entries for multiple on-premises SharePoint vulnerabilities, including remote code execution flaws CVE-2025-49701 and CVE-2025-49704 and spoofing flaw CVE-2025-49706. These July 8 advisories mark the initial public patch/disclosure point in the provided references.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

China-Linked Hackers Exploit SharePoint ToolShell Flaws to Breach Governments and Telecoms | Mallory