HomeTechnologyChinese hackers breach 100+ organizations using SharePoint flaws, says Microsoft

Chinese hackers breach 100+ organizations using SharePoint flaws, says Microsoft

Microsoft’s detailed attribution and response to the exploitation of SharePoint vulnerabilities signal an urgent need for public and private sector organizations to strengthen defenses. As Chinese actors continue to exploit critical systems, timely patching and robust endpoint protection remain essential to thwarting targeted cyberattacks.

July 23, 2025 / 08:20 IST
Story continues below Advertisement
Microsoft
Microsoft

Microsoft has disclosed an ongoing wave of cyberattacks targeting on-premises SharePoint servers, attributing the campaign to multiple Chinese nation-state threat actors. The company’s cybersecurity team observed exploitation of newly disclosed spoofing and remote code execution (RCE) vulnerabilities, tracked as CVE-2025-49706 and CVE-2025-49704. These vulnerabilities do not affect SharePoint Online, which is hosted via Microsoft 365.

According to Microsoft’s threat intelligence division, the actors have been actively leveraging these exploits since early July, with increasing frequency in recent days. This activity is part of what Microsoft describes as a broader pattern of Chinese cyber operations aimed at espionage and theft of sensitive information.

Story continues below Advertisement

Exploitation by Chinese threat groups

Microsoft has specifically named three China-linked actors: Linen Typhoon, Violet Typhoon, and a third group tracked as Storm-2603. These actors are using the SharePoint vulnerabilities to gain initial access to vulnerable, internet-facing SharePoint servers. Once inside, attackers are deploying web shells — particularly variants of spinstall0.aspx — to maintain persistence and steal server machine keys.