Overview
The SharePoint ToolShell Exploitation campaign (MITRE ATT&CK ID C0058) was conducted in July 2025, per MITRE’s campaign profile, encompassing the first waves of exploitation against incompletely patched spoofing (CVE-2025-49706) and remote code execution (CVE-2025-49704) vulnerabilities affecting on-premises Microsoft SharePoint servers. MITRE documents that these were later patched and reissued as CVE-2025-53770 and CVE-2025-53771 once the incompleteness of the original fixes became apparent. Per MITRE’s citations, the ToolShell vulnerabilities were widely exploited, including by China-based ransomware actor Storm-2603 and espionage actors Threat Group-3390 and ZIRCONIUM. The campaign targeted finance, education, energy, and healthcare sectors across Asia, Europe, and the United States.
Timeline
Per MITRE ATT&CK’s ingested data, this campaign’s documented activity window is dated to July 2025 (start and end recorded as the same month in our ingested data — a short, intense exploitation wave rather than a long-running operation).
Named actors and tools (per MITRE’s description vs. our relationship data)
MITRE’s description text names three actors — Storm-2603 (ransomware), Threat Group-3390, and ZIRCONIUM (espionage). We checked this directly against MITRE’s raw published STIX bundle (not just our own ingested copy): every relationship object for this campaign is a technique/tool “uses” edge — there is no “attributed-to” edge to any group at all in MITRE’s own source data. This is a genuine gap in MITRE’s upstream data, not an ingestion issue on our side. We report the actor names as MITRE’s own prose synthesis, not as something its structured relationship graph confirms.
What we don’t have
As noted above, the three actors named in MITRE’s description aren’t backed by a structured relationship edge in our ingested data — treat that naming as MITRE’s own synthesized narrative, not independently confirmed by the graph data we queried. We have no independent telemetry or IOC data beyond MITRE’s STIX bundle.
Frequently Asked Questions
What was the SharePoint ToolShell Exploitation campaign? A July 2025 exploitation wave, per MITRE ATT&CK, against on-premises Microsoft SharePoint servers via incompletely patched CVE-2025-49706/49704 (reissued as CVE-2025-53770/53771), exploited by multiple actors.
Who exploited the ToolShell vulnerabilities? Per MITRE’s description text: China-based ransomware actor Storm-2603, and espionage actors Threat Group-3390 and ZIRCONIUM — though this specific naming isn’t backed by a formal relationship edge in our ingested structured data.
Why were there two sets of CVE numbers? Per MITRE’s documentation, the original patches (CVE-2025-49706, CVE-2025-49704) were incomplete, and the vulnerabilities were later reissued as CVE-2025-53770 and CVE-2025-53771 once broader exploitation was observed.
Data sourced from MITRE ATT&CK® (https://attack.mitre.org), campaign ID C0058, aggregated August 29, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more campaign profiles.