CISA has published a malware analysis report with compromise indicators and Sigma rules for "ToolShell" attacks targeting specific Microsoft SharePoint Server versions. "Cyber threat actors have chained CVE-2025-49704 and CVE-2025-49706 (in an exploit chain publicly known as 'ToolShell') to gain unauthorised access to on-premises SharePoint servers," the agency explained in its announcement of the report. "CISA analysed six files including two Dynamic Link-Library (.DLL), one cryptographic key stealer, and three web shells. Cyber threat actors could leverage this malware to steal cryptographic keys and execute a Base64-encoded PowerShell command to fingerprint host system and exfiltrate data." The key vulnerability in SharePoint Server, the "critical"-rated CVE-2025-53770 with a CVSS score of 9.8, built upon the earlier "medium" severity CVE-2025-49706 - a flaw Microsoft thought it had patched last month, only to find it under active exploitation as a zero-day targeting some big names. Linked with other vulnerabilities in an exploit chain dubbed "Toolshell", the vulnerability allows for remote code execution through untrusted data deserialisation, and is known to have been exploited by groups including Linen Typhoon (aka Emissary Panda, APT27), Violet Typhoon (aka Zirconium, Judgment Panda, APT31), and Storm-2603. As of the July 23, the victim count had risen to more than 400 including the US Department of Energy (DOE), which confirmed to The Register that its National Nuclea...
CISA releases malware analysis for Sharepoint Server attack
The Register
·Gareth Halfacree
·Published Aug 7, 2025
·Updated
Affected Software
1 affected component
Microsoft SharePoint Server
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a malware analysis report released by CISA regarding attacks on Microsoft SharePoint Server.
2
What security implications are discussed?
The article highlights vulnerabilities in SharePoint Server that allow threat actors to execute attacks using specific CVEs.
3
What products or software are affected?
The affected software mentioned in the article is Microsoft SharePoint Server.
4
What specific vulnerabilities are identified in the report?
The report identifies CVE-2025-49704 and CVE-2025-49706 as the vulnerabilities exploited by the malware.
5
What type of malware is referenced in the analysis?
The analysis refers to a malware strain named 'ToolShell' used in the attacks.