Just when you thought the SharePoint hacking scandal was over…

Last weekend was the kind that security teams and sysadmins dread; one where a major security issue drops and everyone has to scramble in response. Yes, I’m talking about the global on-premises SharePoint Server zero-day exploit.

ToolShell, or CVE-2025-53770 to be formal, is a critical vulnerability that can lead to remote access and control of on-premises SharePoint servers, no authentication required.

At the time, the researchers from Eye Security who disclosed the ongoing exploits warned that “the risk is not theoretical,” adding that a successful attack enabled threat actors to “access all SharePoint content, system files, and configurations and move laterally across the Windows Domain”.

But it got worse when you realised that those attackers could also steal cryptographic keys, leading to further impersonation attacks. Microsoft responded quickly, issuing patches and providing ample mitigation advice. And that, you might have thought, was that.

Wrong.

SharePoint hack: what happened next

Bad news comes in threes, and so it is here. First, Microsoft has confirmed that Chinese threat actors, which is a less threatening way of saying state-sponsored hackers, have been behind SharePoint Server exploits. Second, the US nuclear security agency is among the victims. And now it has emerged that ransomware is also being deployed.

“Microsoft has observed two named Chinese nation-state actors, Linen Typhoon and Violet Typhoon exploiting these vulnerabilities targeting internet-facing SharePoint servers,” said Microsoft Threat Intelligence.

“In addition, we have observed another China-based threat actor, tracked as Storm-2603, exploiting these vulnerabilities to deploy ransomware.”

That ransomware appears to be Warlock, while Storm-2603 has been tracked in attempts to steal MachineKeys using the on-premises SharePoint vulnerabilities.

“The attackers turning to ransomware are clearly taking advantage of CVE 2025-53770 to gain further access to environments, encrypting sensitive information, before executing ransomware hoping to get a big pay check,” said Kevin Robertson, CTO of Acumen Cyber.

“Which shows that this vulnerability has opened the door to state-sponsored and financially motivated attackers in equal measure.

“While we now have data saying 400 victims have been compromised,” Robertson warned, “this could be a drop in the ocean in comparison with the reality. CVE 2025-53770 could be the ghost that continues haunt us for some time…”

Industry reaction

Meanwhile, Dr Kolochenko, CEO at ImmuniWeb and a Fellow at the British Computer Society, said that “given that exploitation of this vulnerability is quite noisy, those attacks should have been detected much earlier”.

And he’s not wrong, this really is the security scandal that keeps on giving.

It is, Kolochenko concluded, “an alarming indicator that the reportedly compromised companies and governmental agencies still fail to properly implement a multilayered approach to their cyber defense in order to prevent successful exploitation of a zero-day vulnerability and to stop attackers at least in the middle of the kill chain.”

Recent articles by Davey

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.