One intrusion, two cyberattackers: Uncovering parallel threat activity
This report details a complex ransomware intrusion involving two unrelated threat actors operating simultaneously within the same environment. The first actor, Storm-2603, targeted on-premises SharePoint servers exploiting known vulnerabilities and conducting reconnaissance for local file inclusion weaknesses. They used legitimate tools like Velociraptor with SYSTEM privileges for environment mapping and established multiple remote access channels. Privilege escalation and defense evasion techniques were employed, including creating new administrator accounts and tampering with memory protections. Concurrently, a second threat actor used DLL sideloading and custom backdoors, adding complexity and obscuring detection. Microsoft’s DART team responded by containing the intrusion, correlating telemetry, and providing guidance to strengthen defenses.
AI Analysis
Technical Summary
A multi-stage ransomware intrusion uncovered by Microsoft’s DART revealed two parallel threat actors operating simultaneously. The first actor, Storm-2603, exploited known vulnerabilities in on-premises SharePoint servers since mid-2025 and performed reconnaissance for local file inclusion vulnerabilities. They deployed Velociraptor with SYSTEM privileges to map the environment and established persistence via Cloudflare tunneling, Zoho Assist, and SSH configured through Visual Studio Code. Privilege escalation involved creating new local and domain administrator accounts, and defense evasion included using a vulnerable driver to tamper with memory protections. A second, unrelated threat actor used malicious DLL sideloading and custom backdoors, complicating detection and attribution. Microsoft responded with coordinated containment, telemetry correlation, and targeted guidance to improve security posture. The case highlights the challenge of detecting overlapping cyberattacks and the importance of broad visibility, identity security, and coordinated incident response.
Potential Impact
The intrusion enabled sustained unauthorized access to the victim environment by two distinct threat actors, complicating detection and response efforts. The attackers achieved environment mapping with high privileges, established multiple remote access channels, escalated privileges by creating administrator accounts, and evaded defenses by tampering with memory protections. The presence of two simultaneous threat actors increased the complexity and risk of data compromise, persistence, and potential ransomware impact. The overlapping activities obscured the full scope of the intrusion, increasing the likelihood of prolonged dwell time and damage.
Mitigation Recommendations
Microsoft’s DART team successfully contained the intrusion and stabilized the environment. Organizations are advised to prioritize rigorous patching and vulnerability management, especially for internet-facing systems, to reduce initial access risk. Strengthening identity security is critical to limit escalation and persistence. Customers should establish broad, continuous visibility by deploying endpoint protection and centralizing telemetry. Monitoring and restricting the use of trusted administrative and remote access tools can reduce exploitation opportunities. Maintaining tested incident response playbooks and ensuring rapid isolation of compromised entities will help reduce dwell time. The vendor advisory does not indicate that no action is required; these mitigations are recommended to prevent similar attacks.
One intrusion, two cyberattackers: Uncovering parallel threat activity
Description
This report details a complex ransomware intrusion involving two unrelated threat actors operating simultaneously within the same environment. The first actor, Storm-2603, targeted on-premises SharePoint servers exploiting known vulnerabilities and conducting reconnaissance for local file inclusion weaknesses. They used legitimate tools like Velociraptor with SYSTEM privileges for environment mapping and established multiple remote access channels. Privilege escalation and defense evasion techniques were employed, including creating new administrator accounts and tampering with memory protections. Concurrently, a second threat actor used DLL sideloading and custom backdoors, adding complexity and obscuring detection. Microsoft’s DART team responded by containing the intrusion, correlating telemetry, and providing guidance to strengthen defenses.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
A multi-stage ransomware intrusion uncovered by Microsoft’s DART revealed two parallel threat actors operating simultaneously. The first actor, Storm-2603, exploited known vulnerabilities in on-premises SharePoint servers since mid-2025 and performed reconnaissance for local file inclusion vulnerabilities. They deployed Velociraptor with SYSTEM privileges to map the environment and established persistence via Cloudflare tunneling, Zoho Assist, and SSH configured through Visual Studio Code. Privilege escalation involved creating new local and domain administrator accounts, and defense evasion included using a vulnerable driver to tamper with memory protections. A second, unrelated threat actor used malicious DLL sideloading and custom backdoors, complicating detection and attribution. Microsoft responded with coordinated containment, telemetry correlation, and targeted guidance to improve security posture. The case highlights the challenge of detecting overlapping cyberattacks and the importance of broad visibility, identity security, and coordinated incident response.
Potential Impact
The intrusion enabled sustained unauthorized access to the victim environment by two distinct threat actors, complicating detection and response efforts. The attackers achieved environment mapping with high privileges, established multiple remote access channels, escalated privileges by creating administrator accounts, and evaded defenses by tampering with memory protections. The presence of two simultaneous threat actors increased the complexity and risk of data compromise, persistence, and potential ransomware impact. The overlapping activities obscured the full scope of the intrusion, increasing the likelihood of prolonged dwell time and damage.
Mitigation Recommendations
Microsoft’s DART team successfully contained the intrusion and stabilized the environment. Organizations are advised to prioritize rigorous patching and vulnerability management, especially for internet-facing systems, to reduce initial access risk. Strengthening identity security is critical to limit escalation and persistence. Customers should establish broad, continuous visibility by deploying endpoint protection and centralizing telemetry. Monitoring and restricting the use of trusted administrative and remote access tools can reduce exploitation opportunities. Maintaining tested incident response playbooks and ensuring rapid isolation of compromised entities will help reduce dwell time. The vendor advisory does not indicate that no action is required; these mitigations are recommended to prevent similar attacks.
Technical Details
- Article Source
- {"url":"https://www.microsoft.com/en-us/security/blog/2026/06/22/one-intrusion-two-cyberattackers-uncovering-parallel-threat-activity/","fetched":true,"fetchedAt":"2026-06-22T17:15:50.607Z","wordCount":1560}
Threat ID: 6a396dcceed863c81e2f5fa2
Added to database: 06/22/2026, 17:15:56 UTC
Last enriched: 06/22/2026, 17:16:04 UTC
Last updated: 06/22/2026, 21:53:57 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.