TechCrunch News 07月22日 22:45
Google, Microsoft say Chinese hackers are exploiting SharePoint zero-day
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

安全研究人员发现,中国支持的黑客组织正在利用微软SharePoint的一个零日漏洞(CVE-2025-53770)。该漏洞允许攻击者窃取自托管SharePoint服务器的敏感私钥,进而远程植入恶意软件,访问存储在服务器上的文件和数据,甚至渗透到同一网络内的其他系统。微软已确认至少有两个已知的中国背景黑客组织“Linen Typhoon”和“Violet Typhoon”以及一个名为“Storm-2603”的组织正在利用此漏洞。这些攻击最早可追溯到7月7日,已有数十个组织(包括政府部门)受到影响。尽管微软已发布补丁,但安全专家警告,运行自托管SharePoint版本的客户应假定其系统已遭泄露。中国驻华盛顿大使馆未立即回应置评请求,中国政府一贯否认参与网络攻击。

🛡️ **零日漏洞被利用**:安全研究人员发现,中国支持的黑客组织正在利用微软SharePoint的一个零日漏洞(CVE-2025-53770)。这意味着微软在漏洞被广泛利用之前没有足够的时间发布补丁。该漏洞允许攻击者窃取自托管SharePoint服务器的敏感私钥。

💻 **攻击手段与影响**:一旦私钥被盗,攻击者就可以远程植入恶意软件,获取服务器上存储的文件和数据,并进一步访问同一网络内的其他系统。这可能导致敏感信息的泄露和网络安全的大范围瘫痪。

🕵️ **已知黑客组织参与**:微软已确认,至少有两个已知的中国背景黑客组织“Linen Typhoon”(专注于窃取知识产权)和“Violet Typhoon”(窃取用于间谍活动的私人信息)以及一个名为“Storm-2603”的组织(曾与勒索软件攻击有关)在利用此漏洞。这些攻击最早可追溯到7月7日。

🌐 **广泛的攻击范围**:该漏洞的利用导致了大规模的攻击,已有数十个组织,包括政府部门在内的客户受到了影响。安全专家警告,运行自托管SharePoint版本的客户应假定其系统可能已经遭到入侵。

🇨🇳 **中国政府的回应**:中国驻华盛顿大使馆未立即回应记者的置评请求。中国政府长期以来一直否认参与网络攻击,尽管其并未明确否认所有指控。此次事件是近年来与中国相关的最新一起黑客攻击活动。

Security researchers at Google and Microsoft say they have evidence that hackers backed by China are exploiting a zero-day bug in Microsoft SharePoint, as companies around the world scramble to patch the flaw.

The bug, known officially as CVE-2025-53770 and discovered last weekend, allows hackers to steal sensitive private keys from self-hosted versions of SharePoint, a software server widely used by companies and organizations to store and share internal documents. Once exploited, an attacker can use the bug to remotely plant malware and gain access to the files and data stored within, as well as gain access to other systems on the same network.

In a blog post on Tuesday, Microsoft said it had observed at least two previously identified China-backed hacking groups it calls “Linen Typhoon” and “Violet Typhoon” exploiting the SharePoint zero-day. Microsoft says Linen Typhoon is focused on stealing intellectual property, while Violet Typhoon steals private information to be used for espionage.

Microsoft also attributed the ongoing hacks to a third China-backed hacking group it named “Storm-2603,” representing a hacking group about which the company has less information. The company noted, however, that the hackers have been linked to ransomware attacks in the past.

According to Microsoft, the three hacking groups were observed exploiting the zero-day vulnerability to break into vulnerable SharePoint servers as far back as July 7.

Charles Carmakal, the chief technology officer at Google’s incident response unit Mandiant, told TechCrunch in an email that “at least one of the actors responsible” was a China-nexus hacking group, but noted that “multiple actors are now actively exploiting this vulnerability.”

Dozens of organizations have already been hacked, including across the government sector. The bug, regarded as a zero-day because the vendor — Microsoft, in this case — had no time to issue a patch before it was actively exploited. Microsoft has since rolled out patches for all affected versions of SharePoint, but security researchers have warned that customers running self-hosted versions of SharePoint should assume they have already been compromised.

Techcrunch event

San Francisco | October 27-29, 2025

A spokesperson for the Chinese Embassy in Washington D.C. did not immediately return a request for comment. The Chinese government has long rebuffed allegations that it has carried out cyberattacks, though it has not always explicitly denied its involvement.

This is the latest hacking campaign linked to China in recent years. Hackers backed by China were accused of targeting self-hosted Microsoft Exchange email servers in 2021 as part of a mass-hacking campaign. According to a recent Justice Department indictment accusing two Chinese hackers of masterminding the breaches, the so-called “Hafnium” hacks compromised contact information and private mailboxes from more than 60,000 affected servers.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

SharePoint 零日漏洞 网络攻击 中国黑客 网络安全
相关文章