A SharePoint vulnerability gave Chinese hackers access to government systems

This month's Microsoft security update failed to fully patch a critical vulnerability in SharePoint server software, paving the way for a large-scale global cyber-espionage campaign, according to a timeline reviewed by Reuters.

On Tuesday, a Microsoft spokesperson confirmed that the initial patch — intended to fix the vulnerability discovered during a hacking competition in May — did not work. However, the company has since issued additional patches which it says have resolved the issue.

It remains unclear who exactly is behind the attack, which affected around 100 organizations over the weekend. The scale of malicious activity is expected to grow, as other hacker groups may join in.

Microsoft's blog states that at least two Chinese hacking groups — Linen Typhoon and Violet Typhoon — as well as a third, also based in China, are involved in the attacks.

Microsoft and Google (Alphabet’s division) both stated that Chinese-linked hackers are likely behind the first wave of attacks. China traditionally denies involvement in any cyberattacks.

In response to Reuters, the Chinese embassy in Washington stated that China opposes all forms of cyberattacks and condemns "groundless accusations."

The vulnerability that enabled these attacks was first identified in May during a hacking contest in Berlin, organized by cybersecurity firm Trend Micro. It offered a $100,000 reward for zero-day exploits — previously unknown flaws — targeting software such as SharePoint.

Among the potential targets was the U.S. National Nuclear Security Administration, responsible for the country’s nuclear arsenal. According to Bloomberg, data from this agency was also accessed, though no leak of confidential or classified information has been confirmed.

A researcher from Viettel, a Vietnamese military-controlled telecom company, discovered the vulnerability during the May event, named it ToolShell, and demonstrated its use. He received $100,000 through Trend Micro’s Zero Day initiative.

Trend Micro emphasized that software vendors are responsible for timely patching. “Patches sometimes fail. This has happened with SharePoint before,” the company said in a statement.

In its July 8 security update, Microsoft classified the vulnerability as critical and released patches. However, within 10 days, cybersecurity firms observed a wave of malicious activity targeting the same SharePoint servers.

British firm Sophos reported Monday that attackers developed exploits capable of bypassing Microsoft’s patches.

The number of potentially vulnerable ToolShell targets remains very high. According to search engine Shodan, which tracks internet-connected devices, hackers could potentially compromise over 8,000 servers.

These servers are located in the networks of auditing firms, banks, healthcare providers, industrial companies, U.S. government agencies, and international organizations.

The Shadowserver Foundation, which scans the internet for vulnerabilities, counted over 9,000 potentially compromised servers, calling it a conservative estimate. Most affected are in the U.S. and Germany.

Germany’s Federal Office for Information Security (BSI) stated Tuesday that no government SharePoint servers were breached, though some were vulnerable to ToolShell.