• News/
  • https://www.theregister.com/2025/08/07/cisa_releases_malware_analysis/

CISA releases malware analysis for Sharepoint Server attack

The Register
·
Gareth Halfacree
·
Published Aug 7, 2025
·
Updated

CISA has published a malware analysis report with compromise indicators and Sigma rules for "ToolShell" attacks targeting specific Microsoft SharePoint Server versions. "Cyber threat actors have chained CVE-2025-49704 and CVE-2025-49706 (in an exploit chain publicly known as 'ToolShell') to gain unauthorised access to on-premises SharePoint servers," the agency explained in its announcement of the report. "CISA analysed six files including two Dynamic Link-Library (.DLL), one cryptographic key stealer, and three web shells. Cyber threat actors could leverage this malware to steal cryptographic keys and execute a Base64-encoded PowerShell command to fingerprint host system and exfiltrate data." The key vulnerability in SharePoint Server, the "critical"-rated CVE-2025-53770 with a CVSS score of 9.8, built upon the earlier "medium" severity CVE-2025-49706 - a flaw Microsoft thought it had patched last month, only to find it under active exploitation as a zero-day targeting some big names. Linked with other vulnerabilities in an exploit chain dubbed "Toolshell", the vulnerability allows for remote code execution through untrusted data deserialisation, and is known to have been exploited by groups including Linen Typhoon (aka Emissary Panda, APT27), Violet Typhoon (aka Zirconium, Judgment Panda, APT31), and Storm-2603. As of the July 23, the victim count had risen to more than 400 including the US Department of Energy (DOE), which confirmed to The Register that its National Nuclea...

Read full article

Affected Software

1 affected component
Microsoft SharePoint Server
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a malware analysis report released by CISA regarding attacks on Microsoft SharePoint Server.

2

What security implications are discussed?

The article highlights vulnerabilities in SharePoint Server that allow threat actors to execute attacks using specific CVEs.

3

What products or software are affected?

The affected software mentioned in the article is Microsoft SharePoint Server.

4

What specific vulnerabilities are identified in the report?

The report identifies CVE-2025-49704 and CVE-2025-49706 as the vulnerabilities exploited by the malware.

5

What type of malware is referenced in the analysis?

The analysis refers to a malware strain named 'ToolShell' used in the attacks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203