ToolShell is the name used for a SharePoint exploitation chain and the associated intrusion activity targeting on-premises Microsoft SharePoint Server. The activity has been tied to multiple vulnerabilities, including CVE-2025-49704 and CVE-2025-49706, and later bypass-related flaws CVE-2025-53770 and CVE-2025-53771, which enabled authentication bypass and remote code execution against vulnerable internet-facing SharePoint deployments. Affected platforms include SharePoint Server 2016, 2019, and Subscription Edition; SharePoint Online is not affected.
In observed intrusions, attackers used crafted requests to SharePoint endpoints to achieve code execution, deploy ASPX-based web shells, and steal ASP.NET MachineKey material. Theft of machine keys enabled persistence and post-compromise access, including the ability to maintain access after patching if key material was not rotated. Subsequent tradecraft included execution of PowerShell and command shells from SharePoint worker processes, deployment of additional payloads, host and environment discovery, credential theft in some cases, lateral movement, and follow-on ransomware activity. Reporting also describes a shift from easily detected web-shell deployment toward in-memory payloads to reduce detection.
ToolShell activity has been attributed primarily to China-linked threat actors Linen Typhoon, Violet Typhoon, and Storm-2603. Linen Typhoon and Violet Typhoon have been associated with espionage-oriented targeting of government, defense, telecommunications, academic, nonprofit, and other organizations. Storm-2603 has been linked to financially motivated operations, including ransomware deployment, and has been reported using ToolShell-derived access for broader post-exploitation. Victims have included government agencies, critical infrastructure, universities, and enterprises worldwide, with hundreds of organizations reportedly affected during the 2025 exploitation waves.
Although some reporting referred to ToolShell as being named after a custom remote access trojan, the supplied facts consistently support ToolShell primarily as an exploit chain and campaign label rather than a distinct malware family. Malware observed in ToolShell intrusions has included web shells, loaders, backdoors, and ransomware deployed after exploitation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
On July 19, 2025, security researchers and enterprise defenders began tracking a large-scale exploitation campaign targeting on-premises Microsoft SharePoint Servers (CVE-2025-53770). On July 19th, Microsoft confirmed that a zero day vulnerability impacting on-premises Microsoft SharePoint Servers, dubbed “ToolShell”. CVE-2025-53770 has been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on July 20, 2025.
Researchers also identified Linen Typhoon, Violet Typhoon, and Storm-2603 had in fact started using the two flaws (CVE-2025-49706 and CVE-2025-49704) as zero-days, based on its investigation into ongoing attacks on SharePoint Servers. CVE-2025-49704 : Type: Unauthenticated File Upload Allows arbitrary .aspx files (webshells) to be written to accessible paths.
Researchers also identified Linen Typhoon, Violet Typhoon, and Storm-2603 had in fact started using the two flaws (CVE-2025-49706 and CVE-2025-49704) as zero-days, based on its investigation into ongoing attacks on SharePoint Servers. CVE-2025-49706 : Type: XAML Deserialization Enables post-auth remote code execution (RCE).
CVE-2025-53771 : Type: Input Validation / Path Traversal Used to overwrite or plant files in sensitive directories, aiding persistence.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
According to Microsoft, cyber threat actors have chained CVE-2025-49706 (a network spoofing vulnerability) and CVE-2025-49704 (a remote code execution (RCE) vulnerability) in an exploit chain known as “ToolShell” to gain unauthorized access to on-premise SharePoint servers.
According to Microsoft, cyber threat actors have chained CVE-2025-49706 (a network spoofing vulnerability) and CVE-2025-49704 (a remote code execution (RCE) vulnerability) in an exploit chain known as “ToolShell” to gain unauthorized access to on-premise SharePoint servers.
According to Microsoft, cyber threat actors have chained CVE-2025-49706 (a network spoofing vulnerability) and CVE-2025-49704 (a remote code execution (RCE) vulnerability) in an exploit chain known as “ToolShell” to gain unauthorized access to on-premise SharePoint servers.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
Additional analysis determined these events are likely the result of active, malicious deployment of an exploit leveraging ‘ToolShell.’ ... ToolShell collectively refers to the chained exploitation of two SharePoint vulnerabilities ... threat actors are in fact using ToolShell to exploit a new 0-day vulnerability
59 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named exploit chain referenced as prior SharePoint attack activity against unpatched servers.
Exploit chain against on-prem Microsoft SharePoint enabling unauthenticated RCE; observed used as a zero-day in targeted incidents against North American government orgs.
Referenced as a prior-quarter exploitation surge involving public-facing applications; specific functionality not described in this content.
ToolShell is an exploit tool used to target Microsoft SharePoint via CVE-2025-53770, enabling unauthenticated remote code execution through crafted POST requests.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.