Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

One intrusion, two cyberattackers: Uncovering parallel threat activity

0
Medium
Vulnerability
Published: 06/22/2026 (06/22/2026, 16:00:00 UTC)
Source: Microsoft Security Blog

Description

This report details a complex ransomware intrusion involving two unrelated threat actors operating simultaneously within the same environment. The first actor, Storm-2603, targeted on-premises SharePoint servers exploiting known vulnerabilities and conducting reconnaissance for local file inclusion weaknesses. They used legitimate tools like Velociraptor with SYSTEM privileges for environment mapping and established multiple remote access channels. Privilege escalation and defense evasion techniques were employed, including creating new administrator accounts and tampering with memory protections. Concurrently, a second threat actor used DLL sideloading and custom backdoors, adding complexity and obscuring detection. Microsoft’s DART team responded by containing the intrusion, correlating telemetry, and providing guidance to strengthen defenses.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/22/2026, 17:16:04 UTC

Technical Analysis

A multi-stage ransomware intrusion uncovered by Microsoft’s DART revealed two parallel threat actors operating simultaneously. The first actor, Storm-2603, exploited known vulnerabilities in on-premises SharePoint servers since mid-2025 and performed reconnaissance for local file inclusion vulnerabilities. They deployed Velociraptor with SYSTEM privileges to map the environment and established persistence via Cloudflare tunneling, Zoho Assist, and SSH configured through Visual Studio Code. Privilege escalation involved creating new local and domain administrator accounts, and defense evasion included using a vulnerable driver to tamper with memory protections. A second, unrelated threat actor used malicious DLL sideloading and custom backdoors, complicating detection and attribution. Microsoft responded with coordinated containment, telemetry correlation, and targeted guidance to improve security posture. The case highlights the challenge of detecting overlapping cyberattacks and the importance of broad visibility, identity security, and coordinated incident response.

Potential Impact

The intrusion enabled sustained unauthorized access to the victim environment by two distinct threat actors, complicating detection and response efforts. The attackers achieved environment mapping with high privileges, established multiple remote access channels, escalated privileges by creating administrator accounts, and evaded defenses by tampering with memory protections. The presence of two simultaneous threat actors increased the complexity and risk of data compromise, persistence, and potential ransomware impact. The overlapping activities obscured the full scope of the intrusion, increasing the likelihood of prolonged dwell time and damage.

Mitigation Recommendations

Microsoft’s DART team successfully contained the intrusion and stabilized the environment. Organizations are advised to prioritize rigorous patching and vulnerability management, especially for internet-facing systems, to reduce initial access risk. Strengthening identity security is critical to limit escalation and persistence. Customers should establish broad, continuous visibility by deploying endpoint protection and centralizing telemetry. Monitoring and restricting the use of trusted administrative and remote access tools can reduce exploitation opportunities. Maintaining tested incident response playbooks and ensuring rapid isolation of compromised entities will help reduce dwell time. The vendor advisory does not indicate that no action is required; these mitigations are recommended to prevent similar attacks.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.microsoft.com/en-us/security/blog/2026/06/22/one-intrusion-two-cyberattackers-uncovering-parallel-threat-activity/","fetched":true,"fetchedAt":"2026-06-22T17:15:50.607Z","wordCount":1560}

Threat ID: 6a396dcceed863c81e2f5fa2

Added to database: 06/22/2026, 17:15:56 UTC

Last enriched: 06/22/2026, 17:16:04 UTC

Last updated: 06/22/2026, 21:53:57 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses