Threat Intelligence, Vulnerability Management

Global ToolShell attacks launched by Salt Typhoon

China Flag Made of Binary Code and Chinese Symbols on Red Backgr

Chinese state-sponsored threat operation Salt Typhoon has harnessed the critical Microsoft SharePoint ToolShell flaw, tracked as CVE-2025-53770, to facilitate malware attacks against multiple organizations around the world, The Register reports.

Attacks against a Middle Eastern telecommunications firm and a pair of African government departments involved ToolShell exploitation to deploy the Zingdoor backdoor that enables system data gathering, file uploads and downloads, and arbitrary command execution, according to Symantec and Carbon Black researchers.

Other intrusions, which were aimed at a European finance firm, a Middle Eastern government department, and an African state technology agency, were discovered to have involved the ShadowPad trojan and KrustyLoader backdoor. Vulnerable SQL servers and Apache HTTP servers with Adobe ColdFusion software were also targeted by Salt Typhoon to compromise a U.S. university and a pair of South American government agencies.

Another report from Trend Micro revealed joint Salt Typhoon and Flax Typhoon operations, with the former conducting initial access while the latter performs subsequent compromise.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds