One intrusion, two cyberattackers: Uncovering parallel threat activity
Microsoft's Detection and Response Team (DART) has published a detailed report on a sophisticated cyberattack that revealed the simultaneous operation of two independent threat actors within a single network intrusion. What began as a standard ransomware investigation quickly escalated into a far more intricate scenario, demonstrating the evolving complexity of modern cyber threats. This incident showcased how adversaries are increasingly blending tactics and operating in parallel, thereby obscuring signals and complicating detection and response efforts.
The DART investigation uncovered a multi-stage intrusion where one threat actor, identified as Storm-2603, had been exploiting vulnerabilities in on-premises SharePoint servers since mid-2025. This actor conducted reconnaissance for additional entry points while simultaneously attempting initial access through other vulnerabilities. Once inside, Storm-2603 focused on establishing persistence and control, leveraging legitimate tools like Velociraptor with SYSTEM-level privileges to map the environment. They also set up multiple remote access channels using Cloudflare tunneling, Zoho Assist, and SSH connections via Visual Studio Code, effectively blending malicious activity with trusted administrative behaviors. Privilege escalation followed, with new local and domain administrator accounts created to maintain access.
The report underscores several critical takeaways for security teams. Firstly, isolated security signals are often insufficient to paint a complete picture of an ongoing attack. Organizations must invest in connected telemetry across their environments to enable comprehensive detection, investigation, and correlation of events. Secondly, the incident highlighted the risk associated with legitimate tools being co-opted by attackers. Continuous monitoring and strict controls over trusted administrative and remote access tools are essential to prevent their misuse for persistence and lateral movement.
Furthermore, the DART team emphasized the necessity of preparing for rapid and coordinated incident response. Maintaining well-tested incident response playbooks and ensuring that teams can swiftly isolate compromised users, devices, and access paths are crucial for reducing the attackers' dwell time and mitigating the overall impact of a breach. The case also stressed the importance of closing common gaps in exposure, identity, and visibility. This includes rigorous patching and vulnerability management, particularly for internet-facing systems, to reduce initial access risks, and strengthening identity security to limit threat actor escalation and persistence.
In essence, the findings from this complex intrusion serve as a stark reminder that cyber defense strategies must evolve to counter adversaries who are increasingly sophisticated and adaptable. Organizations need to prioritize a holistic approach to security, integrating robust detection capabilities with agile and coordinated response mechanisms to safeguard their digital assets against multi-faceted threats.
Read original source