ZeroHour
Security Affairspublished ()ingested @securityaffairs

China-linked hackers exploit patched ToolShell flaw to breach Middle East telecom

criticalVulnerability exploited in the wildimportance 60CVE-2025-53770CVE-2021-36942

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-36942
Unauthenticated LSA Spoofing (PetitPotam NTLM Relay) in Microsoft Windows

CVE-2021-36942 is a spoofing flaw in the Windows Local Security Authority (LSA), widely known as "PetitPotam," that lets an unauthenticated network attacker trick a Windows host into authenticating with NTLM to a machine the attacker controls. It is triggered remotely with no privileges and no user interaction (CVSS 3.1 AV:N/AC:L/PR:N/UI:N) by sending crafted requests that coerce the target system to authenticate. By relaying that coerced authentication to other services, an attacker can impersonate the machine — most critically a domain controller — and escalate toward domain-administrator access, producing a high confidentiality impact. All listed Windows Server releases are affected, with domain controllers and certificate-services servers as the highest-value targets. The flaw is actively exploited in the wild: it was added to CISA's KEV on 2021-11-03 with known ransomware use (LockFile and Babuk campaigns chained it with Exchange flaws), and Microsoft has released Windows updates to address it.

Do: Apply Microsoft's Windows updates per vendor instructions, prioritizing domain controllers and servers running Active Directory Certificate Services. As interim hardening, require SMB signing and restrict NTLM authentication per Microsoft guidance, and review authentication logs for unexpected NTLM connections from domain controllers to certificate-services endpoints.

7.566% KEV ransomware PoC
  • Microsoft Windows (per CISA affected listing) as listed by CISA
  • Microsoft Windows Server 2004 as listed in CISA/CPE data
  • Microsoft Windows Server 2008 as listed in CISA/CPE data
  • +4 more
massmillions of Windows Server deployments; hundreds of thousands of SMB-exposed hosts in public internet scans
CVE-2025-53770
Unauthenticated Deserialization RCE in Microsoft SharePoint Server on-premises

CVE-2025-53770 is a deserialization of untrusted data vulnerability (CWE-502) in Microsoft SharePoint Server on-premises that allows an unauthorized attacker to execute code over a network. It is triggered when the server deserializes attacker-controlled data, can be chained with CVE-2025-53771, and it bypasses the fixes issued for CVE-2025-49704, meaning the earlier patches are insufficient. Successful exploitation yields remote code execution on the SharePoint server, and ransomware operators are known to be using it. Any organization running SharePoint Server on-premises is affected, particularly internet-facing deployments and end-of-life versions such as SharePoint Server 2013 and earlier that can no longer be patched. The flaw is being actively exploited — it was added to CISA's KEV on 2025-07-20 with known ransomware use — and EPSS assigns it a 100% probability of exploitation within 30 days.

Do: Apply Microsoft's updated SharePoint Server security updates that fix CVE-2025-53770 — these include more robust protection than the earlier CVE-2025-49704 updates — and ensure the companion CVE-2025-53771 is also addressed, following CISA and vendor mitigation instructions for supported versions. Disconnect public-facing SharePoint Server 2013 or earlier (EOL/EOS) instances, minimize internet exposure of supported servers, and hunt for signs of compromise given the known ransomware exploitation.

9.8100% KEV ransomware PoC ×3
  • Microsoft SharePoint Server (on-premises) Specific version ranges not enumerated in the source data; Microsoft SharePoint on-premises is affected. CISA notes SharePoint Server 2013 and earlier are EOL/E
mass≈25,000–100,000 internet-exposed on-premises SharePoint servers (public internet-wide scans); total on-prem installed base plausibly >1M users
Full article726 words · extracted from securityaffairs.com · click to collapse

China-based threat actors exploited ToolShell SharePoint flaw CVE-2025-53770 soon after its July patch.

China-linked threat actors exploited the ToolShell SharePoint flaw vulnerability, tracked as CVE-2025-53770, to breach a telecommunications company in the Middle East after it was addressed by Microsoft in July 2025.

“China-based attackers used the ToolShell vulnerability (CVE-2025-53770) to compromise a telecoms company in the Middle East shortly after the vulnerability was publicly revealed and patched in July 2025.” reads the report published by Broadcom’s Symantec Threat Hunter Team.

According to Broadcom’s Symantec Threat Hunter Team, the attackers, linked to Glowworm (aka Earth Estries) and UNC5221, breached multiple targets, including two African government departments, two South American agencies, and a U.S. university. The hackers used tools like Zingdoor and KrustyLoader, and targeted SQL and Apache ColdFusion servers. A fake “mantec.exe” (masquerading as Symantec software) sideloaded malware. Additional victims include a state tech agency in Africa, a Middle Eastern ministry, and a European finance firm.

In July, Microsoft warned of a SharePoint zero-day vulnerability, tracked as CVE-2025-53770 (CVSS score of 9.8), which is under active exploitation. The vulnerability is a deserialization of untrusted data in on-premises Microsoft SharePoint Server, an unauthorized attacker could exploit the vulnerability to execute code over a network.

Microsoft later confirmed that three China-based groups, Budworm, Violet Typhoon aka (Sheathminer), and Storm-2603, had exploited ToolShell, with the latter deploying Warlock ransomware.

Also targeted were government departments in an African country, as well as government agencies in South America, a university in the U.S., as well as likely a state technology agency in an African country, a government department in the Middle East, and a finance company in a European country.

According to Broadcom’s Symantec Threat Hunter Team, the attacks involved the exploitation of CVE-2025-53770, a now-patched security flaw in on-premise SharePoint servers that could be used to bypass authentication and achieve remote code execution.

Malicious activity at a Middle Eastern telecom began on July 21, 2025, two days after ToolShell was patched, with attackers using a webshell and DLL sideloading to deploy backdoors and loaders. Zingdoor was sideloaded via a Trend Micro binary to collect data, transfer files and run commands. Threat actors sideloaded the ShadowPad backdoor using a BitDefender binary; it supports plug-in updates and has been used alongside ransomware. On July 25, attackers dropped the Rust-based KrustyLoader to fetch second-stage payloads, evade analysis and self-delete. Attackers also employed a variety of publicly available and living-off-the-land tools, including Certutil for file downloads, GoGo Scanner for network scanning, Revsocks for proxying traffic through firewalls, and Sysinternals’ Procdump, PowerSploit’s Minidump, and LsassDumper to extract LSASS process memory and steal credentials.

“An exploit for the Windows LSA Spoofing Vulnerability, CVE-2021-36942 (aka PetitPotam), was also executed.” continues the post. “PetitPotam is an exploitation technique that allows for a threat actor within a compromised network to steal credentials and authentication information from Windows Servers such as a Domain Controller to gain full control of the domain. This is likely used for lateral movement or privilege escalation.”

The attacks reveal ToolShell was exploited by a broader range of China-based threat actors than initially known. While overlaps exist with Glowworm activity, attribution remains uncertain. The numerous victims suggest mass scanning for vulnerable servers, followed by targeted intrusions focused on credential theft and long-term, covert access, indicating a likely espionage-driven campaign.

The attacks reveal ToolShell was exploited by a broader range of China-based threat actors than initially known. While overlaps exist with Glowworm activity, attribution remains uncertain. The numerous victims suggest mass scanning for vulnerable servers, followed by targeted intrusions focused on credential theft and long-term, covert access, indicating a likely espionage-driven campaign.

“There is some overlap in the types of victims and some of the tools used between this activity and activity previously attributed to Glowworm. However, we do not have sufficient evidence to conclusively attribute this activity to one specific group, though we can say that all evidence points to those behind it being China-based threat actors.” concludes the report. “The large number of apparent victims of this activity is also notable. This may indicate that the attackers were carrying out an element of mass scanning for the ToolShell vulnerability, before then carrying out further activity only on networks of interest.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, ToolShell)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/183800/security/china-linked-hackers-exploit-patched-toolshell-flaw-to-breach-middle-east-telecom.html