ATT&CKReferencesTrend Micro SharePoint Attacks JUL 2025

Trend Micro SharePoint Attacks JUL 2025

Trend Micro Research. (2022, July 22). Proactive Security Insights for SharePoint Attacks (CVE-2025-53770 and CVE-2025-53771). Retrieved October 15, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns1

Procedure examples8

TechniqueUsed byProcedure example
T1027.010
Command Obfuscation
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors executed Base64-encoded PowerShell commands.

T1071.001
Web Protocols
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors issued HTTP `POST` requests to web shells with spoofed or empty Referrer headers, to circumvent authorization controls.

T1074.001
Local Data Staging
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors staged stolen data from web.config files to debug_dev.js.

T1119
Automated Collection
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors used a command shell to automatically iterate through web.config files to expose and collect machineKey settings.

T1190
Exploit Public-Facing Application
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors exploited authentication bypass and remote code execution vulnerabilities (CVE-2025-49706 and CVE-2025-49704) against on-premises SharePoint servers. This activity was characterized by crafted `POST` requests to the ToolPane endpoint `/_layouts/15/ToolPane.aspx`.

T1505.003
Web Shell
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors followed exploitation of SharePoint servers with installation of a malicious .aspx web shell (spinstall0.aspx) that was written to the `_layouts/15/` directory, granting persistent HTTP-based access.

T1552.001
Credentials In Files
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors accessed web.config and machine.config to extract MachineKey values, enabling them to forge legitimate VIEWSTATE tokens for future deserialization payloads.

T1620
Reflective Code Loading
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors reflectively loaded payloads using `System.Reflection.Assembly.Load`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.