Microsoft Says Chinese Hackers Exploiting SharePoint Flaws

☑︎#VoteDemocrat

The Original
WOAT
Supporter
Joined
Dec 9, 2012
Messages
328,916
Reputation
-34,075
Daps
635,182
Reppin
The Deep State





Microsoft Says Chinese Hackers Exploiting SharePoint Flaws
Summarize
National governments in Europe, the Middle East impacted Attackers have stolen sign-in credentials, sensitive data

By Jake Bleiberg, Ryan Gallagher, and Patrick Howell O'Neill
July 22, 2025 at 10:31 AM EDT
A person uses a Microsoft Corp. Surface tablet in Hong Kong.
Photographer: Billy H.C. Kwok/Bloomberg
Microsoft Corp. accused Chinese state-sponsored hackers of using flaws in its SharePoint document management software in a hacking campaign that has targeted businesses and government agencies around the world.

In a blog post on Tuesday, the tech giant identified two groups supported by the Chinese government, Linen Typhoon and Violet Typhoon, as leveraging flaws in SharePoint software used by customers who managed it on their own networks, as opposed to in the cloud. Another hacking group based in China, which Microsoft calls Storm-2603, also exploited the SharePoint vulnerabilities, according to the blog.

“Investigations into other actors also using these exploits is still ongoing,” Microsoft said. “With the rapid adoption of these exploits, Microsoft assesses with high confidence that threat actors will continue to integrate them into their attacks.”

A representative for the Chinese Embassy in Washington didn’t immediately respond to a request for comment.

Other cybersecurity researchers have said multiple hacking groups have been making use of the flaws in the popular Microsoft software, and some also indicated that Chinese attackers were likely among them.

Hackers have already used the flaw to break into the systems of national governments in Europe and the Middle East, according to a person familiar with the matter. In the US, they’ve assessed government systems, including ones belonging to the Education Department, Florida’s Department of Revenue and the Rhode Island General Assembly, said the person, who asked not to be identified discussing sensitive information.

The types of organizations targeted, the techniques and other initial evidence is consistent with Chinese state-sponsored espionage, said Eugenio Benincasa, a researcher at the Swiss university ETH Zurich who specializes in analyzing Chinese attacks.

The security company Eye Security has detected compromises on more than 100 servers representing 60 victims, including organizations in the energy sector, consulting firms and universities. Victims were also located in Saudi Arabia, Vietnam, Oman and the United Arab Emirates, according to the company.

Multiple different hackers are launching attacks through the Microsoft vulnerability, according to representatives of two cybersecurity firms, CrowdStrike Holdings Inc. and Google’s Mandiant Consulting.

Attackers have exploited the vulnerability in SharePoint since at least July 7 in attempted hacks against two “high value targets,” says Adam Meyers, senior vice president at CrowdStrike. The early exploitation resembled government-sponsored activity, and then spread more widely to include hacking that “looks like China,” Meyers said. CrowdStrike’s investigation into the campaign is ongoing, he said.

Microsoft over the weekend released a patch for the vulnerability in servers of the SharePoint document management software. The company said it was still working to roll out other fixes after warnings that hackers were targeting SharePoint clients, using the flaw to enter file systems and execute code.

Representatives of the Department of Education and Rhode Island legislature didn’t respond to calls and emails seeking comment Monday. A Florida Department of Revenue spokesperson, Bethany Wester Cutillo, said in an email that the SharePoint vulnerability is being investigated “at multiple levels of government” but that the state agency “does not comment publicly on the software we use for operations.”

The hackers also breached the systems of a US-based health-care provider and targeted a public university in Southeast Asia, according to a report from a cybersecurity firm reviewed by Bloomberg News. The report doesn’t identify either entity by name, but says the hackers have attempted to breach SharePoint servers in countries including Brazil, Canada, Indonesia, Spain, South Africa, Switzerland, the UK and the US. The firm asked not to be named because of the sensitivity of the information.

In some systems they’ve broken into, the hackers have stolen sign-in credentials, including usernames, passwords, hash codes and tokens, according to a person familiar with the matter, who also spoke on condition that they not be identified discussing the sensitive information.

“This is a high-severity, high-urgency threat,” said Michael Sikorski, chief technology officer and head of threat intelligence for Unit 42 at Palo Alto Networks Inc.

“What makes this especially concerning is SharePoint’s deep integration with Microsoft’s platform, including their services like Office, Teams, OneDrive and Outlook, which has all the information valuable to an attacker,” he said. “A compromise doesn’t stay contained — it opens the door to the entire network.”

Tens of thousands — if not hundreds of thousands — of businesses and institutions worldwide use SharePoint in some fashion to store and collaborate on documents. Microsoft said that attackers are specifically targeting clients running SharePoint servers from their own on-premise networks, as opposed to being hosted and managed by the tech firm. That could limit the impact to a subsection of customers.

“It’s a dream for ransomware operators,” said Silas Cutler, a researcher at Michigan-based cybersecurity firm Censys. He estimated that more than 10,000 companies with SharePoint servers were at risk. The US had the largest number of such firms, followed by the Netherlands, the UK and Canada, he said.

The breaches have drawn new scrutiny to Microsoft’s efforts to shore up its cybersecurity after a series of high-profile failures. The firm has hired executives from places like the US government and holds weekly meetings with senior executives to make its software more resilient. The company’s tech has been subject to several widespread and damaging hacks in recent years, and a 2024 US government report described the company’s security culture as in need of urgent reforms.

The Center for Internet Security, which operates a cybersecurity information sharing system for state and local governments in the US, found more than 1,100 servers that are at risk from the SharePoint vulnerability, said Randy Rose, the organization’s vice president of security operations and intelligence. Rose said more than 100 were likely hacked.

The Washington Post reported that the breach had affected US federal and state agencies, universities, energy companies and an Asian telecommunications company, citing state officials and private researchers.

Eye Security said the vulnerability allows hackers to access SharePoint servers and steal keys that can let them impersonate users or services even after the server is patched. It said hackers can maintain access through backdoors or modified components that can survive updates and reboots of systems.

The SharePoint vulnerabilities, known as “ToolShell,” were first identified in May by researchers at a Berlin cybersecurity conference. In early July, Microsoft issued patches to fix the security holes, but hackers found another way in.

“There were ways around the patches,” which enabled hackers to break into SharePoint servers by tapping into similar vulnerabilities, said Vaisha Bernard, the company’s chief hacker and co-owner. “That allowed these attacks to happen.” The intrusions, he said, were not targeted and instead were aimed at compromising as many victims as possible. After scanning about 8,000 SharePoint servers, Bernard said he has so far identified at least 50 that were successfully compromised.

He declined to identify the identity of organizations that had been targeted, but said they included government agencies and private companies, including “bigger multinationals.” The victims were located in countries in North and South America, the EU, South Africa, and Australia, he added.
 
Top