ATT&CKReferencesPalo Alto SharePoint Vulnerabilities JUL 2025

Palo Alto SharePoint Vulnerabilities JUL 2025

Unit 42. (2025, July 31). Active Exploitation of Microsoft SharePoint Vulnerabilities: Threat Brief (Updated). Retrieved October 15, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns1

Procedure examples19

TechniqueUsed byProcedure example
T1005
Data from Local System
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors extracted information from the compromised systems.

T1027.002
Software Packing
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors UPX-packed malicous payloads including 4L4MD4R ransomware.

T1027.010
Command Obfuscation
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors executed Base64-encoded PowerShell commands.

T1059.001
PowerShell
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors used PowerShell to execute attacker-controlled encoded commands.

T1071.001
Web Protocols
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors issued HTTP `POST` requests to web shells with spoofed or empty Referrer headers, to circumvent authorization controls.

T1074.001
Local Data Staging
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors staged stolen data from web.config files to debug_dev.js.

T1105
Ingress Tool Transfer
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors used a loader to download and execute ransomware.

T1119
Automated Collection
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors used a command shell to automatically iterate through web.config files to expose and collect machineKey settings.

T1140
Deobfuscate/Decode Files or Information
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors decrypted scripts prior to execution.

T1190
Exploit Public-Facing Application
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors exploited authentication bypass and remote code execution vulnerabilities (CVE-2025-49706 and CVE-2025-49704) against on-premises SharePoint servers. This activity was characterized by crafted `POST` requests to the ToolPane endpoint `/_layouts/15/ToolPane.aspx`.

T1486
Data Encrypted for Impact
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors deployed ransomware including 4L4MD4R and Warlock.

T1505.003
Web Shell
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors followed exploitation of SharePoint servers with installation of a malicious .aspx web shell (spinstall0.aspx) that was written to the `_layouts/15/` directory, granting persistent HTTP-based access.

T1552.001
Credentials In Files
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors accessed web.config and machine.config to extract MachineKey values, enabling them to forge legitimate VIEWSTATE tokens for future deserialization payloads.

T1583.001
Domains
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors registered C2 domains to spoof legitimate Microsoft domains.

T1585.002
Email Accounts
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors created Proton mail accounts for communication with organizations infected with ransomware.

T1595.002
Vulnerability Scanning
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors scanned for SharePoint servers vulnerable to CVE-2025-53770.

T1620
Reflective Code Loading
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors reflectively loaded payloads using `System.Reflection.Assembly.Load`.

T1657
Financial Theft
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors demanded ransom payments to unencrypt filesystems and to refrain from publishing sensitive data exfiltrated from victim networks.

T1685
Disable or Modify Tools
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors disabled Microsoft Defender through Registry settings and real-time monitoring via PowerShell.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.