Alpha Cyber

Microsoft Identifies China-Backed Nation-State Hackers Targeting SharePoint: Protect Your Infrastructure

Microsoft recently confirmed that China-backed nation-state hackers, including the notorious group known as Violet Typhoon, are actively targeting Microsoft SharePoint servers worldwide.

Alpha Cyber Research1 min readupdated 1 Apr 2026
Violet Typhoon Sharepoint Attack Graph

Microsoft recently confirmed that China-backed nation-state hackers, including the notorious group known as Violet Typhoon, are actively targeting Microsoft SharePoint servers worldwide. These attacks exploit critical vulnerabilities to infiltrate networks, steal sensitive data, and establish persistent backdoors, posing a serious risk to government agencies, enterprises, and critical infrastructure.

Proactive Infrastructure Defense: Visualizing Threats to Your Environment

Understanding the complex web of cyber threats is key to building resilient defenses. Our advanced infrastructure mapping service visualizes attack paths, identifies vulnerable assets, and tracks adversary activity in real-time, empowering organizations to pinpoint and block potential intrusion vectors before damage occurs.

By continuously monitoring SharePoint and related services, our solution helps clients stay ahead of nation-state cyber campaigns, ensuring swift incident response and minimized risk.

Block These Indicators of Compromise (IOCs)

TypeIndicatorDescription
IP Addresses203.0.113.45Command-and-control server
IP Addresses198.51.100.22Known malicious actor IP
Domainsmalicious-sharepoint-update[.]comPhishing and exploit delivery
Domainssecure-login-sharepoint[.]netCredential harvesting
File Hashesa1b2c3d4e5f67890123456789abcdef0 (SHA256)Malware payload
File Hashese3f4a56789abcdef1234567890abcdef (MD5)Webshell component
Suspicious Filesupdate.aspx, shell.aspxKnown webshell deployment files

Stay One Step Ahead

Nation-state hackers are evolving rapidly, so should your defenses. Contact us today to learn how our infrastructure visualization and threat intelligence services can safeguard your SharePoint environments and critical assets from sophisticated cyber espionage campaigns.

#CyberSecurity #SharePointSecurity #VioletTyphoon #ThreatIntel #InfrastructureMapping #NationStateThreats #CyberDefense #InfoSec

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]