Threat Group: Linen Typhoon, Violet Typhoon, Storm-2603
Threat Type: Remote Code Execution & Spoofing
Exploited Vulnerabilities: CVE-2025-53770 (RCE), CVE-2025-53771 (Spoofing)
Malware Used: ToolShell (spinstall0.aspx)
Threat Score: 🔴 High (8.0/10) – Active exploitation by nation-state actors, persistent access via cryptographic theft, and potential lateral movement across enterprise networks.
Last Threat