Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Campaigns/C0058
MITRE ATT&CK Campaign · 2025–2025

SharePoint ToolShell Exploitation (C0058)

ShareXLinkedInRedditHN

The [SharePoint ToolShell Exploitation](https://attack.mitre.org/campaigns/C0058) campaign was conducted in July 2025 and encompassed the first waves of exploitation against incompletely patched spoofing (CVE-2025-49706) and remote code execution (CVE-2025-49704) vulnerabilities affecting on-premises Microsoft SharePoint servers. Later patched and updated as CVE-2025-53770 and CVE-2025-53771, the ToolShell vulnerabilities were widely exploited including by China-based ransomware actor Storm-2603 and espionage actors [Threat Group-3390](https://attack.mitre.org/groups/G0027) and [ZIRCONIUM](https://attack.mitre.org/groups/G0128). [SharePoint ToolShell Exploitation](https://attack.mitre.org/campaigns/C0058) targeted multiple regions and industries including finance, education, energy, and healthcare across Asia, Europe, and the United States.(Citation: Microsoft SharePoint Exploit JUL 2025)(Citation: Palo Alto SharePoint Vulnerabilities JUL 2025)(Citation: Eye Research ToolShell JUL 2025)(Citation: ESET ToolShell JUL 2025)(Citation: Trend Micro SharePoint Attacks JUL 2025)

▪Techniques used (35)

T1053.005Scheduled TaskT1033System Owner/User DiscoveryT1552.001Credentials In FilesT1027.002Software PackingT1071.001Web ProtocolsT1083File and Directory DiscoveryT1505.003Web ShellT1583.001DomainsT1140Deobfuscate/Decode Files or InformationT1484.001Group Policy ModificationT1003.001LSASS MemoryT1059.001PowerShellT1657Financial TheftT1190Exploit Public-Facing ApplicationT1047Windows Management InstrumentationT1119Automated CollectionT1572Protocol TunnelingT1585.002Email AccountsT1082System Information DiscoveryT1486Data Encrypted for ImpactT1074.001Local Data StagingT1505.004IIS ComponentsT1059.003Windows Command ShellT1027.010Command ObfuscationT1090ProxyT1685Disable or Modify ToolsT1588.002ToolT1569.002Service ExecutionT1112Modify RegistryT1620Reflective Code LoadingT1595.002Vulnerability ScanningT1105Ingress Tool TransferT1570Lateral Tool TransferT1041Exfiltration Over C2 ChannelT1005Data from Local System

▪Software used (4)

S0029PsExectoolS0002MimikatztoolS0508ngroktoolS0357Impackettool
C0058on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.