← Back to list

Chinese Threat Actors Wage War on Unpatched SharePoint Servers

The cybersecurity landscape is perpetually shifting, but some things remain constant, nation-state actors relentless pursuit of valuable…

Anabel kelson · 2025-07-28 13:16 · 51 claps · 2.9 min read
#nation-state #threat-actor #cybercrime #chinese #sharepoint-online
Open on Medium ↗
Wiki topics: GEN · Genomics & Sequencing 🔒 · Cybersecurity

Chinese Threat Actors Wage War on Unpatched SharePoint Servers

The cybersecurity landscape is perpetually shifting, but some things remain constant, nation-state actors relentless pursuit of valuable data and the critical importance of patching vulnerabilities. A recent report from Microsoft sheds light on a concerning trend, multiple Chinese-based threat groups are actively exploiting two critical vulnerabilities (CVE-2025–53770 and CVE-2025–53771) in internet-facing SharePoint servers. This coordinated exploitation, dubbed ‘ToolShell’ by the cybersecurity community, serves as a stark reminder of the high stakes involved in enterprise security and the potential consequences of neglecting patch management.

Microsoft’s Threat Intelligence team has identified three key actors spearheading this campaign: Linen Typhoon (APT27), Violet Typhoon (APT31), and Storm-2603.

Linen Typhoon, also known by a laundry list of aliases including Bronze Union, Budworm, and Emissary Panda, is a Chinese state-backed actor with a history dating back to at least 2010. Their primary targets are foreign embassies, and their objective is to gather intelligence on governments, defense organizations, technology companies, and human rights groups. Linen Typhoon is notorious for employing drive-by compromises and leveraging existing exploits, demonstrating their resourcefulness in exploiting known weaknesses.

Violet Typhoon, operating since at least 2012, specializes in intellectual property theft. Known as Bronze Vinewood and Judgment Panda, they meticulously target organizations in sectors like government, academia, healthcare, and finance to steal data and projects that give them a competitive edge. A hallmark of Violet Typhoon’s approach is persistent vulnerability scanning, enabling them to install web shells on compromised systems and maintain persistent access.

While Microsoft assessed with medium confidence that Storm-2603 is a China-based threat actor, less is known about their specific motivations and affiliations. The tech giant’s threat intelligence team has not yet identified any definitive links between this group and other known Chinese threat actors. However, they have observed Storm-2603 attempting to steal MachineKeys via the SharePoint vulnerabilities, and have seen them deploy Warlock and Lockbit ransomware in the past, suggesting a broader range of potential objectives.

This Microsoft assessment aligns with a previous analysis from Mandiant, reinforcing the conclusion that these exploits are not mere opportunistic attacks but rather part of a broader strategic campaign. BlueVoyant’s Lorri Janssen-Anessi emphasized that this attribution to Chinese nation-state hacking groups underscores the campaign’s strategic nature, likely aimed at gaining initial access, establishing persistence, and attempting to exfiltrate sensitive intelligence data from high-value targets across government, defense, academia and NGOs.

So, what does this mean for organizations using on-premises SharePoint servers? Simply put, if you’re running unpatched, internet-facing systems, you’re squarely in the crosshairs. This is not a theoretical threat; it’s an active campaign with sophisticated actors actively probing for vulnerable systems.

The immediate priority is to apply the necessary patches for CVE-2025–53770 and CVE-2025–53771. Don’t delay this critical task; treat it as a fire drill. Beyond immediate patching, this incident should trigger a broader review of your organization’s security posture:

  • Implement a robust patch management process: Ensure that all systems are promptly patched with the latest security updates. • Harden your SharePoint servers: Follow Microsoft’s security best practices for configuring and securing SharePoint.
  • Implement strong access controls: Restrict access to sensitive data and systems to authorized personnel only. • Monitor your systems for suspicious activity: Deploy intrusion detection and prevention systems to identify and block malicious activity. • Educate your employees about phishing and other social engineering attacks: Attackers often use phishing to gain initial access to systems.

This ToolShell campaign is a potent reminder that cybersecurity is not a one-time fix but an ongoing process. Stay informed about emerging threats, prioritize proactive security measures, and cultivate a culture of security awareness throughout your organization. The cost of complacency is far greater than the investment in robust security practices.


메타데이터
post_id
5024defe9178
slug
chinese-threat-actors-wage-war-on-unpatched-sharepoint-servers-5024defe9178
url
https://medium.com/@Egovibes/chinese-threat-actors-wage-war-on-unpatched-sharepoint-servers-5024defe9178
canonical_url
https://medium.com/@Egovibes/chinese-threat-actors-wage-war-on-unpatched-sharepoint-servers-5024defe9178
author_url
https://medium.com/@Egovibes
status
ok
fetched_at
2026-06-26 03:39:16