CISA published a Malware Analysis Report (MAR) with analysis and associated detection signatures on files related to Microsoft SharePoint vulnerabilities:
- CVE-2025-49704 [CWE-94: Code Injection],
- CVE-2025-49706 [CWE-287: Improper Authentication],
- CVE-2025-53770 [CWE-502: Deserialization of Untrusted Data], and
- CVE-2025-53771 [CWE-287: Improper Authentication]
Cyber threat actors have chained CVE-2025-49704 and CVE-2025-49706 (in an exploit chain publicly known as “ToolShell”) to gain unauthorized access to on-premises SharePoint servers. CISA analyzed six files including two Dynamic Link-Library (.DLL), one cryptographic key stealer, and three web shells. Cyber threat actors could leverage this malware to steal cryptographic keys and execute a Base64-encoded PowerShell command to fingerprint host system and exfiltrate data.
CISA added CVE-2025-49704 and CVE-2025-49706 to its Known Exploited Vulnerabilities Catalog on July 22, 2025, and CVE-2025-53770 on July 20, 2025.
CISA encourages organizations to use the indicators of compromise (IOCs) and detection signatures in this MAR to identify malware.
Downloadable copy of IOCs associated with this malware:
Downloadable copies
[…]
Content was cut in order to protect the source.Please visit the source for the rest of the article.
Read the original article: