ThreatCluster
  • Feed
  • Dashboard
  • Saved
THREAT HUNTING
  • Domains
  • IP Addresses
  • File Hashes
  • CVEs
THREAT INTELLIGENCE
  • APT Groups
  • Ransomware Groups
  • Malware Families
  • Attack Types
  • MITRE ATT&CK
  • Security Standards
  • Vulnerability Types
BUSINESS INTELLIGENCE
  • Companies
  • Industry Sectors
  • Security Vendors
  • Government Agencies
  • Countries
  • Platforms
Home / Feed / Article

Chinese Hackers Exploit SharePoint Vulnerabilities to Deploy Toolsets Includes Backdoor, Ransomware and Loaders

Threat Score:
61
Cybersecurity News
20 hours ago
Part of cluster #1713

Overview

A sophisticated Chinese threat actor has been exploiting critical vulnerabilities in Microsoft SharePoint to deploy an advanced malware toolset dubbed “Project AK47,” according to new research published by Palo Alto Networks Unit 42. The campaign, which has been active since at least March 2025, represents a significant escalation in attacks targeting enterprise SharePoint environments through […]...

Continue Reading on Original Site

Related Articles

5 articles
1

2025-08-07 - Cluster AI Daily Threat Brief

ThreatCluster • 7 hours ago

# Daily Threat Intelligence Brief - August 7, 2025 ## Executive Summary Today’s threat landscape presents a multifaceted challenge, with phishing and ransomware emerging as the most critical threats. Recent reports indicate a surge in sophisticated attacks targeting prominent platforms such as Google and Salesforce, leading to significant user data exfiltration. Phishing tactics, including the use of fake CAPTCHA systems to deliver malware, have further exacerbated vulnerabilities within organ

Score
88
Read more
2
Stop Reacting; Start Anticipating: The Global State of Threat Intelligence

Stop Reacting; Start Anticipating: The Global State of Threat Intelligence

Brighttalk • 16 hours ago

Presented by Jitin Shabadu, Forrester Analyst | Jayce Nichols, Director, Intelligence Solutions, Google Threat Intelligence Group

Score
83
Read more
3

Ransomware plunges insurance company into bankruptcy

Graham Cluley • 14 hours ago

Collapsed company's founder says that its fortunes were hampered by the refusal of authorities to release the criminals' seized funds to victims. in my article on the Fortra blog.

Score
76
Read more
4

Trend Micro fixes two actively exploited Apex One RCE flaws

Security Affairs • 15 hours ago

Trend Micro patched two critical Apex One flaws (CVE-2025-54948, CVE-2025-54987) exploited in the wild, allowing RCE via console injection. Trend Micro released fixes for two critical vulnerabilities, tracked as CVE-2025-54948 and CVE-2025-54987 (CVSS score of 9.4), in Apex One on-prem consoles. The cybersecurity vendor confirmed that both issues were actively exploited in the wild. Both […]

Score
76
Read more
5

Google Discloses Salesforce Hack

Feedburner • 13 hours ago

A Google Salesforce instance may have been targeted as part of a ShinyHunters campaign that hit several major companies.

Score
75
Read more

Save to Folder

Choose a folder to save this article:

Article Intelligence

Key entities and indicators for this article

ATTACK TYPES
Exploit
Exploitation of Public-Facing Applications
Phishing
Ransomware
Remote Code Execution
COMPANIES
Microsoft
Palo Alto Networks
SECURITY VENDORS
CrowdStrike
Palo Alto Networks
Unit 42
PLATFORMS
Microsoft SharePoint
SharePoint
APT GROUPS
Linen Typhoon
Storm-2603
Violet Typhoon
MITRE ATT&CK
T1053
T1059
T1059.001
T1071
T1071.001
MALWARE
4L4MD4R
Project AK47
X2ANYLOCK
RANSOMWARE
4L4MD4R
LockBit
VULNERABILITIES
Data Encryption for Impact
Remote Code Execution
CVES
CVE-2025-49704
CVE-2025-49706
CVE-2025-53770
CVE-2025-53771
DOMAINS
innovationfactory.it
IP ADDRESSES
145.239.97.206
COUNTRIES
China
INDUSTRIES
Cybersecurity
Government
Information Technology
AGENCIES
Department of Homeland Security
National Nuclear Security Administration
IP ADDRESSES
145.239.97.206
DOMAINS
innovationfactory.it
ARTICLE INFORMATION
Article #9126
Published 20 hours ago
Cybersecurity News

We use cookies

We use cookies and similar technologies to enhance your experience, analyse site usage, and assist in our marketing efforts.

Cookie Settings

Essential Cookies

Required for the website to function. Cannot be disabled.

  • Session management and authentication
  • Security and fraud prevention
  • Cookie consent preferences

Analytics Cookies

Help us understand how visitors interact with our website.

  • Plausible Analytics - Privacy-focused usage statistics
  • PostHog - Product analytics and feature tracking
  • Page views and user journey analysis

Performance Cookies

Help us monitor and improve website performance.

  • Page load time monitoring
  • Error tracking and debugging
  • Performance optimisation

Marketing Cookies

Used to track visitors across websites for marketing purposes.

  • Conversion tracking
  • Remarketing campaigns
  • Social media integration