MachineKeyFinder is a malware/detection name referenced by Microsoft Defender Antivirus as Trojan:PowerShell/MachineKeyFinder.DA!amsi in the context of active exploitation of on-premises Microsoft SharePoint Server vulnerabilities CVE-2025-53770 and CVE-2025-53771. The associated Microsoft guidance states these attacks targeted on-premises SharePoint Server customers and involved post-exploitation activity. High-confidence related behaviors and artifacts in the same campaign context include suspicious encoded PowerShell spawned by w3wp.exe and creation of spinstall0.aspx under SharePoint LAYOUTS directories. Microsoft also associated this activity cluster with detections such as Exploit:Script/SuspSignoutReq.A, Exploit:Script/SuspSignoutReqBody.A, and Trojan:Win32/HijackSharePointServer.A, and with Defender for Endpoint alerts including possible web shell installation, possible exploitation of SharePoint server vulnerabilities, suspicious IIS worker process behavior, and IIS worker process loaded suspicious .NET assembly. Microsoft recommended enabling and correctly configuring AMSI, deploying Defender for Endpoint/Antivirus, applying the July 2025 cumulative SharePoint security updates, and rotating SharePoint ASP.NET machine keys followed by IIS restarts. The content does not attribute MachineKeyFinder to a specific threat actor or provide standalone technical details beyond its Defender detection name and campaign context.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
PowerShell-based trojan behavior focused on locating/extracting ASP.NET/SharePoint machine keys (credential/crypto material) to enable persistence or further compromise, detected via AMSI by Microsoft Defender.
MachineKeyFinder [[URL_b3187638_88]] 2025 年 8 月 (v. 5.135)
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.