We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Trojan:Win32/HijackSharePointServer.A
Aliases: No associated aliases
Summary
Trojan:Win32/HijackSharePointServer.A is a new malware released specifically to target unpatched Microsoft SharePoint servers and uses two vulnerabilities (CVE-2025-53770 and CVE-2025-53771) to run remote code, implant web shells, and exfiltrate cryptographic keys. This threat runs even without authentication, and threat actors can gain SYSTEM privileges, infiltrate server internals, and create persistence.
This multi-stage attack chain allows the malware to maintain stealth while compromising SharePoint servers for espionage, ransomware deployment, or further network infiltration.
The vulnerabilities exploited by the malware are patched under KB5002768 for SharePoint Subscription edition, KB5002741 for SharePoint 2019, and KB5002744 for SharePoint 2016.
For more information and guidance from Microsoft, read the following:
Refer to the Mitigation and protection guidance in the Disrupting active exploitation of on-premises SharePoint vulnerabilities blog for details.
Microsoft Defender Antivirus automatically removes threats as they are detected. However, many infections can leave remnant files and system changes. Updating your antimalware definitions and running a full scan might help address these remnant artifacts.
You can also visit our advanced troubleshooting page or search the Microsoft virus and malware community for more help.