---
title: "Threat Intel Content Update: 7/29/2025"
description: Tidal Cyber's threat intelligence content updates for the week of 7/29/2025- Sharepoint Vulnerability Exploits, Interlock Ransomware
---

[Threat Intelligence Content Updates ](https://www.tidalcyber.com/threat-updates)

# [Threat Intel Content Update: 7/29/2025](https://www.tidalcyber.com/threat-updates/threat-intel-content-update-7/29/2025)

 Written by [Tidal Cyber](https://www.tidalcyber.com/threat-updates/author/tidal-cyber) | Jul 30, 2025 12:50:19 PM

#### **Sharepoint Vulnerability Exploits, Interlock Ransomware**

**Threat Content Highlights**

Threat Profiles

- “Trending & Emerging Threats” weekly update: **SharePoint Vulnerability Exploits** 
    - We first released an [object](https://app.tidalcyber.com/campaigns/18f9141f-beab-4dbc-86d3-365a805cb472?tab=4) around this campaign early last week, then updated it with an additional 18 Technique and 10 Group & Software relationships as [additional intelligence](https://www.microsoft.com/en-us/security/blog/2025/07/22/disrupting-active-exploitation-of-on-premises-sharepoint-vulnerabilities/) was published during the week.
    - A range of actors, including multiple with links to China, are using distinct tools to carry out post-compromise data collection and exfiltration after compromising vulnerable on-premises SharePoint servers.

 

Threat Objects

- **Interlock Ransomware**: [New Group](https://app.tidalcyber.com/groups/ec680afc-ea1f-4b08-93b3-56a6c3f1b365?tab=2) featuring 30+ Technique & Software relationships, mainly derived from [CISA’s latest advisory](https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-203a) focused on this ransomware operation.
- Interlock is especially notable as they have been observed using drive-by downloads and “ClickFix” social engineering – initial access methods that are relatively rare in the ransomware landscape (see  [T1189](https://app.tidalcyber.com/tactics/586a5b49-c566-4a57-beb4-e7c667f9c34c/techniques/d4e46fe1-cc6d-4ef0-af72-a4e8dcd71381) and [T1204.004](https://app.tidalcyber.com/tactics/dad2337d-6d35-410a-acc5-da36ff83ee44/techniques/b77f25da-4da7-5d9c-9093-d384ca57616d) respectively, which are both related to the Interlock Group object).

 

[View full post](https://www.tidalcyber.com/threat-updates/threat-intel-content-update-7/29/2025)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Tidal Cyber"
  },
  "dateModified" : "2025-07-30T12:50:19.544Z",
  "datePublished" : "2025-07-30T12:50:19Z",
  "headline" : "Threat Intel Content Update: 7/29/2025",
  "image" : {
    "@type" : "ImageObject",
    "height" : 500,
    "url" : "https://21164103.fs1.hubspotusercontent-na1.net/hubfs/21164103/Threat%20Intelligence%20Content%20Update%20Social.jpg",
    "width" : 900
  },
  "mainEntityOfPage" : "https://www.tidalcyber.com/threat-updates/threat-intel-content-update-7/29/2025",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60,
      "url" : "/hs/hsstatic/content_shared_assets/static-1.4092/img/default-amp-logo.png",
      "width" : 60
    },
    "name" : "Threat Intelligence Content Updates"
  }
}
```