ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Storm-2603 spotted deploying ransomware on exploited SharePoint servers

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-1147
XML Markup RCE in Microsoft .NET Framework, SharePoint, and Visual Studio

CVE-2020-1147 is a remote code execution flaw that exists in Microsoft .NET Framework, .NET Core, SharePoint Enterprise Server, SharePoint Server, Visual Studio 2017, and Visual Studio 2019 when the software fails to check the source markup of XML file input. It is triggered when an application parses attacker-controlled XML — public proofs-of-concept demonstrate exploitation through SharePoint's DataSet/DataTable deserialization, allowing an attacker to run arbitrary code in the context of the affected application or service. An attacker who successfully exploits the flaw gains code execution with the privileges of the parsing process, which on SharePoint servers typically means compromise of a widely used business platform. Organizations running affected .NET Framework, .NET Core, SharePoint, or Visual Studio deployments are affected. Exploitation is confirmed: public PoCs were released around the July 2020 Patch Tuesday fixes, the flaw was added to CISA's Known Exploited Vulnerabilities catalog in November 2021, and news reports describe the Storm-2603 group deploying ransomware on exploited SharePoint servers.

Do: Apply the July 2020 Microsoft security updates for .NET Framework, .NET Core, SharePoint, and Visual Studio, as required by CISA's KEV catalog entry. Prioritize internet-facing SharePoint servers, and hunt for signs of exploitation there given reports of Storm-2603 deploying ransomware on exploited SharePoint servers. Until patched, restrict untrusted XML input handling and limit exposure of SharePoint and other affected services to the internet.

7.894% KEV PoC ×4
  • Microsoft .NET Framework
  • Microsoft .NET Core
  • Microsoft SharePoint Enterprise Server supported versions fixed in July 2020 security updates; PoCs target SharePoint Server 2019
  • +3 more
masshundreds of millions of Windows devices with .NET Framework installed, plus tens of thousands of SharePoint deployments (order of magnitude estimate)
CVE-2025-49704
+1 in the same advisory: …49706
Authenticated Code Injection RCE in Microsoft SharePoint

CVE-2025-49704 is a code injection vulnerability (CWE-94) in Microsoft SharePoint that allows an authorized (authenticated) attacker to execute arbitrary code on the server over the network, by sending requests whose attacker-controlled input SharePoint executes as code. It can be chained with CVE-2025-49706, and Microsoft subsequently issued CVE-2025-53770 as a patch bypass of the original CVE-2025-49704 fix, meaning the CVE-2025-53770 updates provide stronger protection and should be treated as the definitive remediation. Successful exploitation yields remote code execution on the SharePoint server, and CISA added the flaw to the KEV on 2025-07-22 with known ransomware use. Organizations running on-premises SharePoint Server are affected; CISA directs owners of public-facing servers running EOL/EOS versions (SharePoint Server 2013 and earlier) to disconnect them, and operators of supported versions to apply the CISA and vendor mitigations and updates, with cloud SharePoint services governed by BOD 22-01. Exploitation is confirmed in the wild and EPSS assigns a 100% probability of exploitation within 30 days (top percentile), although no public proof-of-concept code is documented.

Do: Apply Microsoft's SharePoint Server updates for CVE-2025-53770, which supersede the original CVE-2025-49704 fixes with more robust protection, prioritizing internet-facing servers. Disconnect public-facing SharePoint servers running EOL/EOS versions (SharePoint Server 2013 and earlier), and for supported versions follow the CISA and vendor mitigations, with cloud services handled per BOD 22-01. Because in-the-wild exploitation and ransomware use are confirmed, hunt for indicators of compromise and ransomware activity on exposed SharePoint servers.

8.8
group max
100% KEV ransomware
  • Microsoft SharePoint CISA lists 'Microsoft SharePoint' without enumerating specific version ranges; the CISA KEV guidance targets on-premises SharePoint Server, calling out SharePoi
masstens of thousands of internet-exposed SharePoint servers per public scans, within a total on-premises install base plausibly exceeding 100,000 deployments…
CVE-2025-53770
Unauthenticated Deserialization RCE in Microsoft SharePoint Server on-premises

CVE-2025-53770 is a deserialization of untrusted data vulnerability (CWE-502) in Microsoft SharePoint Server on-premises that allows an unauthorized attacker to execute code over a network. It is triggered when the server deserializes attacker-controlled data, can be chained with CVE-2025-53771, and it bypasses the fixes issued for CVE-2025-49704, meaning the earlier patches are insufficient. Successful exploitation yields remote code execution on the SharePoint server, and ransomware operators are known to be using it. Any organization running SharePoint Server on-premises is affected, particularly internet-facing deployments and end-of-life versions such as SharePoint Server 2013 and earlier that can no longer be patched. The flaw is being actively exploited — it was added to CISA's KEV on 2025-07-20 with known ransomware use — and EPSS assigns it a 100% probability of exploitation within 30 days.

Do: Apply Microsoft's updated SharePoint Server security updates that fix CVE-2025-53770 — these include more robust protection than the earlier CVE-2025-49704 updates — and ensure the companion CVE-2025-53771 is also addressed, following CISA and vendor mitigation instructions for supported versions. Disconnect public-facing SharePoint Server 2013 or earlier (EOL/EOS) instances, minimize internet exposure of supported servers, and hunt for signs of compromise given the known ransomware exploitation.

9.8100% KEV ransomware PoC ×3
  • Microsoft SharePoint Server (on-premises) Specific version ranges not enumerated in the source data; Microsoft SharePoint on-premises is affected. CISA notes SharePoint Server 2013 and earlier are EOL/E
mass≈25,000–100,000 internet-exposed on-premises SharePoint servers (public internet-wide scans); total on-prem installed base plausibly >1M users
CVE-2025-53771
Improper Authentication in Microsoft SharePoint Server Enables Network Spoofing

CVE-2025-53771 is an improper authentication flaw (CWE-287) in Microsoft's on-premises SharePoint Server that allows an unauthenticated remote attacker to conduct spoofing over the network. Per the CVSS vector, exploitation requires no privileges and no user interaction, so an attacker who can reach the SharePoint server over the network can trigger it directly. Successful exploitation lets the attacker impersonate an authenticated user or component, producing limited but real impact on confidentiality and integrity (CVSS 6.5, medium). Any organization running on-premises SharePoint Server is affected, particularly those exposing it to the internet; no specific version numbers are provided in the source data, so defenders should consult Microsoft's advisory for their edition. No public PoC exists and it is not yet in CISA's KEV, but exploitation likelihood is near-certain (EPSS 99.7%, 100th percentile), and Microsoft has confirmed active China-linked nation-state exploitation of the closely related SharePoint ToolShell vulnerability chain, which has hit roughly 400 organizations including U.S. federal agencies.

Do: Apply Microsoft's SharePoint Server security updates that ship this fix as soon as possible, prioritizing internet-facing servers, and treat this as urgent because it was patched alongside the actively exploited ToolShell chain. While patching, review authentication and web-server logs on SharePoint hosts for unexpected successful logons or anomalous requests that could indicate spoofing or compromise, and restrict network access to SharePoint (VPN, firewall rules, segmentation) if patching must be delayed.

6.5100%
  • Microsoft SharePoint Server (on-premises)
largeTens of thousands of internet-facing SharePoint Server deployments, with a total on-prem installed base plausibly in the hundreds of thousands (estimate)
Full article894 words · extracted from helpnetsecurity.com · click to collapse

One of the groups that, in the past few weeks, has been exploiting vulnerabilities in on-prem SharePoint installation has been observed deploying Warlock ransomware, Microsoft shared on Wednesday.

First attack spotted on July 7th

On Saturday, Microsoft announced that attackers have been spotted exploiting a zero-day variant (CVE-2025-53770) of a SharePoint vulnerability (CVE-2025-49706) that the company partially addressed with updates released on July 8th, 2025.

In the intervening days, some things have become clearer but other murkier.

For example, despite still saying it’s CVE-2025-53770 that is being exploited, the company’s blog post that pins the attacks on various Chinese threat actors says that the vulnerabilities being exploited are CVE-2025-49706, a spoofing vulnerability, and CVE-2025-49704, a remote code execution vulnerability. (Both partially patched in early July.)

Microsoft recently also cleared up the confusion on which new vulnerability was a variant (i.e., a patch bypass) of an older one:

  • CVE-2025-53770 (insecure deserialization vulnerability allowing unauthenticated attackers to execute code over a network, i.e., remotely execute code) is related to CVE-2025-49704 (code injection flaw allowing authorized attackers to execute code over a network)
  • CVE-2025-53771 (path traversal flaw that allows an unauthorized attacker to perform spoofing over a network) is related to CVE-2025-49706 (improper authentication vulnerability that allows authorized attackers to perform spoofing over a network and may allow them to to view sensitive information and make some changes to disclosed information).

While CVE-2025-53771 is the only one of the four that Microsoft’s security advisory and CISA have yet to mark/confirm as being exploited, other security companies say that it is.

Whatever the case may be, Microsoft has stated that attackers have been attempting to exploit CVE-2025-49704 and CVE-2025-49706 to gain initial access to target organizations since at least July 7h.

Check Point Research also said that the first exploitation attempts they detected happened on the same date, and that the target was a major Western government. Since then, more specific targets, both in the US and around the world, have been confirmed.

Storm-2603 exploits SharePoint vulnerabilities, deploys ransomware

“The TTPs employed in these exploit attacks align with previously observed activities of these threat actors,” Microsoft’s threat intelligence analysts say.

The threat actors in question are Chinese state-sponsored groups Linen Typhoon and Violet Typhoon, which concentrate on stealing intellectual property and espionage (respectively), and Storm-2603, another suspected China-based threat actor that seems primarily focused on deploying ransomware.

In past attacks, Storm-2603 deployed Warlock and Lockbit ransomware – this time around they reportedly stuck to using the former.

Storm-2603’s attack chain (Source: Microsoft Threat Intelligence)

In these latest attacks, Storm-2603 has been:

  • Gaining access to vulnerable on-prem SharePoint servers by exploiting the aforementioned vulnerabilities
  • Performing reconnaissance (i.e., enumerating user context and validating privilege levels)
  • Disabling Microsoft Defender protections through direct registry modifications
  • Establishing persistence by installing a web shell, creating scheduled tasks and manipulating Internet Information Services (IIS) components to load suspicious .NET assemblies
  • Extracting plaintext credentials from Local Security Authority Subsystem Service (LSASS) memory with Mimikatz
  • Moving laterally using PsExec (to escalate privileges), Impacket toolkit, and Windows Management Instrumentation (WMI)
  • Modifying Group Policy Objects (GPO) to distribute Warlock ransomware in compromised environments.

More attacks by different groups are expected

The attacks witnessed so far are likely just the beginning.

With technical details on the original ToolShell attack chain (CVE-2025-49706 + CVE-2025-49704) having been made public, and CVE-2025-53770 PoC exploits being published on GitHub, other skilled attackers are likely to join the rush to take advantage of the (too slowly shrinking) pool of still vulnerable internet-facing on-prem SharePoint servers.

“SharePoint exploitation has now entered the parasitic phase,” SANS Internet Storm Center noted.

“We are seeing hits to more then 100 distinct possible web shell URLs. Some of them may just be guesses, but a good part of them are likely webshells created by the Toolshell exploit over the last couple days.”

All organizations’ whose on-prem SharePoint servers were internet-facing in the last month should operate under the assumption they’ve been compromised and proceed to investigate, install updates / mitigations, and rotate the ASP.NET machine keys.

UPDATE (July 25, 2025, 06:00 a.m. ET):

Kaspersky researchers have released a technical analysis of the exploits used and explained how Microsoft did an incomplete job with the CVE-2025-49704 and CVE-2025-49706 fixes.

They also pointed out the similarity between CVE-2020-1147, an old NET Framework, SharePoint Server, and Visual Studio RCE vulnerability, and CVE-2025-49704/CVE-2025-53770.

“In fact, if we compare the exploit for CVE-2020-1147 and an exploit for CVE-2025-49704/CVE-2025-53770, we can see that they are almost identical. This makes CVE-2025-53770 an updated fix for CVE-2020-1147,” they said.

Finally, they warned that despited complete patches now being available, they believe this chain of exploits will continue being used by attackers for a long time.

“We have been observing the same situation with other notorious vulnerabilities, such as ProxyLogon, PrintNightmare, or EternalBlue. While they have been known for years, many threat actors still continue leveraging them in their attacks to compromise unpatched systems. We expect the ToolShell vulnerabilities to follow the same fate, as they can be exploited with extremely low effort and allow full control over the vulnerable server.”

UPDATE (August 4, 2025, 08:45 a.m. ET):

Palo Alto Networks researchers have spotted ToolShell exploitation attempts leading to the deployment of 4L4MD4R ransomware.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/07/24/storm-2603-spotted-deploying-ransomware-on-exploited-sharepoint-servers/