Chinese Hackers Exploit SharePoint Flaws in ‘Project AK47’ Campaign
Researchers from Palo Alto Networks Unit 42 have uncovered a state-sponsored Chinese threat actor tracked as Storm-2603 by Microsoft and CL-CRI-1040 by Unit 42 exploiting four critical Microsoft SharePoint vulnerabilities (CVE-2025–49704, CVE-2025–49706, CVE-2025–53770, CVE-2025–53771) to deliver a custom malware suite dubbed Project AK47. Active since March 2025, the campaign uses the ToolShell exploit chain to…
Read More “Chinese Hackers Exploit SharePoint Flaws in ‘Project AK47’ Campaign” »
