CARDS
CARDS
The SharePoint ToolShell Exploitation campaign was conducted in July 2025 and encompassed the first waves of exploitation against incompletely patched spoofing (CVE-2025-49706) and remote code execution (CVE-2025-49704) vulnerabilities affecting on-premises Microsoft SharePoint servers. Later patched and updated as CVE-2025-53770 and CVE-2025-53771, the ToolShell vulnerabilities were widely exploited including by China-based ransomware actor Storm-2603 and espionage actors Threat Group-3390 and ZIRCONIUM. SharePoint ToolShell Exploitation targeted multiple regions and industries including finance, education, energy, and healthcare across Asia, Europe, and the United States.
Last updated May 24, 2026, 8:00 PM EDT
Evidence Boundary
Bottom Line Up Front
The SharePoint ToolShell Exploitation campaign was conducted in July 2025 and encompassed the first waves of exploitation against incompletely patched spoofing (CVE-2025-49706) and remote code execution (CVE-2025-49704) vulnerabilities affecting on-premises Microsoft SharePoint servers. Later patched and updated as CVE-2025-53770 and CVE-2025-53771, the ToolShell vulnerabilities were widely exploited including by China-based ransomware actor Storm-2603 and espionage actors Threat Group-3390 and ZIRCONIUM. SharePoint ToolShell Exploitation targeted multiple regions and industries including finance, education, energy, and healthcare across Asia, Europe, and the United States.[1][2][3][4][5][6]
Potential disruption, data theft, extortion, and recovery cost depending on victim environment.[1][2][3][4][5][6]
Map local telemetry to the listed ATT&CK techniques before assuming exposure. Review identity, endpoint, network egress, and cloud audit evidence for campaign-specific behavior. Keep attribution and victimology source-bound unless corroborated by local evidence.[1][2][3][4][5][6]
Decision Summary
The SharePoint ToolShell Exploitation campaign was conducted in July 2025 and encompassed the first waves of exploitation against incompletely patched spoofing (CVE-2025-49706) and remote code execution (CVE-2025-49704) vulnerabilities affecting on-premises Microsoft SharePoint servers. Later patched and updated as CVE-2025-53770 and CVE-2025-53771, the ToolShell vulnerabilities were widely exploited including by China-based ransomware actor Storm-2603 and espionage actors Threat Group-3390 and ZIRCONIUM. SharePoint ToolShell Exploitation targeted multiple regions and industries including finance, education, energy, and healthcare across Asia, Europe, and the United States.
The retained record scopes this as ransomware / extortion / apt / nation-state activity during 2025-07-01 to 2025-07-01. Potential disruption, data theft, extortion, and recovery cost depending on victim environment.[1][2][3][4][5][6]
Map local telemetry to the listed ATT&CK techniques before assuming exposure. Review identity, endpoint, network egress, and cloud audit evidence for campaign-specific behavior. Keep attribution and victimology source-bound unless corroborated by local evidence.[1][2][3][4][5][6]
Confirmed reporting is separated from attribution, victim, and prevalence claims that the retained sources do not establish. Confidence: High for MITRE-tracked campaign metadata and ATT&CK relationships; operational currentness should be validated..[1][2][3][4][5][6]
Actor Mapping
Targeting
Tradecraft
Tools / Observables
Source Reconciliation
Campaign rows are retained as source-backed context. Actor mappings do not automatically merge actor records; SOCRadar, MITRE, Mandiant, CrowdStrike, Microsoft, and other future sources can disagree on boundaries, aliases, or campaign ownership.
Campaign row is compressed for directory seeding. Confirm actor linkage, infrastructure, and targeting with source-specific reports and local telemetry.
IntelliOS
None Found
Citations