CISA Releases Malware Analysis... Note

CISA Releases Malware Analysis Report Associated with Microsoft SharePoint Vulnerabilities

CISA has released a Malware Analysis Report (MAR) detailing vulnerabilities in Microsoft SharePoint. The report focuses on four specific CVEs: CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771. Threat actors are actively chaining CVE-2025-49704 and CVE-2025-49706, a method known as "ToolShell," to access on-premises SharePoint servers without authorization. CISA's analysis identified six malicious files, including DLLs, a key stealer, and web shells. This malware can be used to steal cryptographic keys and exfiltrate data after fingerprinting host systems. Consequently, CISA added these CVEs to its Known Exploited Vulnerabilities Catalog on July 20th and 22nd, 2025. Organizations are urged to utilize the provided indicators of compromise and detection signatures to identify the malware. Downloadable IOCs and SIGMA detection rules are available for this purpose. Further details on the malware and YARA rules can be found in MAR-251132.c1.v1. CISA provides this information for informational purposes without endorsing specific commercial products.