Microsoft has confirmed that state-backed Chinese threat actors have hacked on-premises SharePoint servers, targeting sensitive business data through newly discovered vulnerabilities.
The company has released critical security updates and is urging all customers using on-premises versions of SharePoint Server to patch their systems without delay.
Chinese Threat Actors Behind the Breach
Microsoft’s investigation links the attacks to three China-based hacking groups: Linen Typhoon, Violet Typhoon, and Storm-2603. These groups have exploited two severe vulnerabilities – CVE-2025-49706, a spoofing flaw, and CVE-2025-49704, a remote code execution vulnerability – affecting on-premises SharePoint servers, but not SharePoint Online within Microsoft 365.
The company warned that the attacks are ongoing and likely to intensify. “We have high confidence that threat actors will continue to integrate these exploits into their attacks against unpatched on-premises SharePoint systems,” Microsoft said in a blog post.
How the Attacks Work
The attackers exploited SharePoint by sending crafted POST requests to vulnerable servers, allowing them to upload malicious scripts like spinstall0.aspx. These web shells enabled them to steal ASP.NET MachineKey data, which could then be used to maintain persistent access to compromised systems.
Microsoft’s telemetry shows that the hackers have also deployed PowerShell-based payloads post-exploitation, enabling the theft of encryption keys and other sensitive configuration data.
Recommended reading
- Report: Vulnerability Exploitation Surge Endangers Cybersecurity
- Half of SMEs Struggle to Keep Up With Security Threats
- 1 in 4 SMEs Find Remote Working A Key Cybersecurity Concern
Profile of the Threat Actors
-
Linen Typhoon, active since 2012, is focused on stealing intellectual property, particularly from organisations linked to government, defence, strategic planning, and human rights.
-
Violet Typhoon, active since 2015, specialises in espionage, targeting NGOs, think tanks, media organisations, higher education, and sectors like finance and healthcare across the US, Europe, and East Asia.
-
Storm-2603, assessed with “medium confidence” as a China-based group, has previously deployed ransomware strains such as Warlock and Lockbit but appears to be using these vulnerabilities primarily for key theft and long-term infiltration.
Microsoft’s Emergency Response
Microsoft’s Security Response Center (MSRC) has a comprehensive blog post detailing the attacks and the required security updates. Patches have been released for:
-
SharePoint Server Subscription Edition
-
SharePoint Server 2019
-
SharePoint Server 2016
The updates also address two new vulnerabilities, CVE-2025-53770 (remote code execution) and CVE-2025-53771 (security bypass), which are related to the original flaws.
To mitigate the risk of exploitation, Microsoft recommends:
-
Applying all available security updates immediately.
-
Rotating ASP.NET MachineKeys and restarting IIS services.
-
Enabling Antimalware Scan Interface (AMSI) and Microsoft Defender Antivirus in Full Mode on all SharePoint servers.
-
Deploying Microsoft Defender for Endpoint or equivalent endpoint protection tools.
If AMSI cannot be enabled, Microsoft suggests disconnecting vulnerable servers from the internet or placing them behind an authenticated proxy or VPN until patched.





