operational Vulnerabilities & CVEscritical

Microsoft attributes on-premises SharePoint exploitation to Chinese state actors

Tue, Jul 22, 2025, 08:00 PM UTC·Jul 22, 2025· Private Sector (PRIVSEC)

Summary

Bottom line: Microsoft tied active exploitation of on-premises SharePoint flaws to Linen Typhoon, Violet Typhoon and Storm-2603, with post-exploitation key theft enabling persistent access. Rotate machine keys after patching, because patching alone does not evict the actor.

Key claims· extracted from reporting

  • Bottom line: Microsoft tied active exploitation of on-premises SharePoint flaws to Linen Typhoon, Violet Typhoon and Storm-2603, with post-exploitation key theft enabling persistent access.Med · 30%
    numbernamed entity×6
  • Rotate machine keys after patching, because patching alone does not evict the actor.Low · 10%
    named entity

Heuristic extraction, verify against the original report before citing.

Tags· click to alert

Story timeline

4 updates · 91 days
  1. Jul 22, 2025·criticalcurrentMicrosoft Threat Intelligence
    Microsoft attributes on-premises SharePoint exploitation to Chinese state actors

Key takeaways

The three things worth remembering from this item.

  1. 1Bottom line: Microsoft attributes on-premises SharePoint exploitation to Chinese state actors[1]
  2. 2APT31 activity is the driver here, and the objective is what should shape your response, not the tool names.[1][2]
  3. 3Corroboration matters: Microsoft Threat Intelligence is one source, so confidence rises only when a second independent outlet reports the same facts.[1]

Concepts in this story

Each concept opens in layers: plain English, technical, then expert.

APT31

MSS, Wuhan State Security Bureau

APT31 is a MSS, Wuhan State Security Bureau linked hacking group. In plain terms, they break into politicians, journalists, think tanks and stay there.

Why it matters
Criminal extortion is the most likely intrusion any US organization will actually face, and it now routinely disrupts hospitals, schools and local government.[1][2]
Common misconception
That ransomware is only an encryption problem. Data theft and extortion continue even when backups restore cleanly.
Cyber Kill ChainNIST CSF 2.0, Identify, Detect, Respond
Sources for this concept
  1. [1]DOJ indicts 7 APT31 hackers for targeting IPAC members· Public incident reporting· 2024-03-25 00:00Z
  2. [2]Microsoft attributes on-premises SharePoint exploitation to Chinese state actors· Microsoft Threat Intelligence· 2025-07-22 20:00Z
Sources for these takeaways
  1. [1]Microsoft attributes on-premises SharePoint exploitation to Chinese state actors· Microsoft Threat Intelligence· 2025-07-22 20:00Z
  2. [2]DOJ indicts 7 APT31 hackers for targeting IPAC members· Public incident reporting· 2024-03-25 00:00Z

Related concepts

Threads that build naturally on what you just read.

Cyber Kill ChainSequence model behind the attack chain diagram
NIST CSF 2.0Govern, Identify, Protect, Detect, Respond, Recover

Knowledge check

Five questions. Answers explain the reasoning, not just the result.

Question 1 of 3

At which level of analysis does this reporting sit?

Question 2 of 3

What severity has this item been assigned in the feed?

Question 3 of 3

What is the correct handling classification of everything on this platform?

Answer all 3 to check.
Estimated mastery
First time on this material.
New · 0/100