Infoglobez
Live Coverage
Sign in Sign up
Trending: Champions League Transfer News Premier League World Cup
Infoglobez
AI & ML

Dual Threats: Investigation Reveals Overlapping Attacks via Vulnerable SharePoint Servers

A recent Microsoft investigation uncovered how two distinct threat actors exploited unpatched SharePoint vulnerabilities, complicating containment efforts.

Jun 23, 2026 | 3 min read
Sign in to save

The spotlight has shifted to a troubling scenario in cybersecurity: multiple attackers operating concurrently within the same network, obfuscating each other’s activities. This revelation surfaced during a Microsoft Detection and Response Team (DART) investigation, initially sparked by ransomware incidents attributed to a group known as Storm-2603.

Initially, investigators tracked what appeared to be a single intrusion; however, deeper analysis uncovered a second attack chain, characterized by different tools, infrastructure, and end goals. Microsoft emphasized this in its cyberattacks report, stating, “This case highlights a growing reality: modern attacks are not always isolated events. Sometimes they are overlapping campaigns.” This complexity significantly hindered the investigation, as one actor's maneuvers obscured signs of the other.

Competing Intrusions in a Single Network

The breach originated from vulnerabilities in the organization's on-premises SharePoint servers. Storm-2603 successfully exploited these weaknesses, establishing a foothold within the network. Their tactics included the use of Cloudflare Tunnel, Zoho Assist, Visual Studio Code Remote SSH, and Velociraptor. To further gain control, they created unauthorized administrator accounts and disabled security protocols through compromised drivers before deploying ransomware.

As the investigators pieced together the timeline of events, they identified suspicious activity that didn’t match the typical patterns of the ransomware group. This led to the discovery of another attacker, which employed techniques such as DLL sideloading, custom backdoors, and attempts to access Active Directory credentials, illustrating a separate but concurrent threat operating in the same environment.

According to Microsoft, this situation is a reminder of how easily two distinct threat actors can engage in parallel activity, obscuring the scope of the breach. Vibhum Dubey, an independent cybersecurity analyst, pointed out that overlapping intrusions are more common than many in the field acknowledge. “Most incident responders hesitate to conclude that multiple unrelated actors are operating in the same environment,” he noted, emphasizing that the simultaneous presence of different groups often stems from similar vulnerabilities being exploited rather than any form of coordination.

The Scope of the Attack

The investigation deepened when researchers detected that the attacks had spread beyond the initial network. DART confirmed another organization had fallen victim to the same Storm-2603 ransomware tactics, illustrating the adversary's reach and effectiveness.

Dubey explained the challenges that overlapping intrusions create during containment efforts. Ejecting one actor can inadvertently alert another that remained unnoticed. Success in containing both threats comes down to solid threat intelligence, as DART demonstrated by using a structured response strategy that aggregated telemetry across identities, endpoints, and cloud services to pinpoint abnormal behaviors.

The efficacy of DART’s approach involved daily updates with affected customers while collaborating with Microsoft Threat Intelligence, maintaining a clear overview of the two concurrent attacks. Only through meticulous correlation of various data points was the full extent of their struggle against the intrusion made evident.

Key Takeaways for Enterprises

In light of these findings, Microsoft has urged businesses to prioritize the patching of their internet-facing systems, particularly focusing on on-premises SharePoint vulnerabilities. They advocate for treating privileged identity management as a fundamental security focus, applying enhanced controls and monitoring.

Moreover, deploying comprehensive endpoint protection, centralizing data monitoring, and limiting access to remote tools known to be exploited by attackers are crucial strategies. Companies should keep tested incident response playbooks on hand to enable the rapid isolation of compromised accounts.

Dubey bluntly pointed out the root cause, arguing that “an internet-facing box sat unpatched long enough for more than one actor to walk through the door.” He suggests that the subsequent challenges encountered stem directly from that initial oversight. Timely intervention and proactive defenses could prevent similar incidents in the future.

Microsoft has yet to respond to requests for further commentary on the situation.

Source: Robert Garcia · www.csoonline.com
Sign in to join the discussion.