→ Back to Home
Cloud Security

One intrusion, two cyberattackers: Uncovering parallel threat activity

What began as a routine ransomware investigation quickly revealed a far more intricate scenario for Microsoft's Detection and Response Team (DART). Their latest cyberattack series report details a single intrusion that uncovered parallel activity from two distinct, unrelated threat actors operating simultaneously within the same environment. This complex situation challenged traditional assumptions about how multi-stage intrusion campaigns unfold, especially across hybrid environments, by blending tactics and obscuring signals. The investigation revealed a multi-stage intrusion where one primary attacker, identified as Storm-2603, had been actively targeting on-premises SharePoint servers since mid-2025. This group exploited known vulnerabilities and conducted reconnaissance for additional entry points, such as probing for local file inclusion weaknesses. Once initial access was likely achieved, Storm-2603 focused on establishing persistence and control. They deployed legitimate tools like Velociraptor with SYSTEM-level privileges to map the environment and set up multiple remote access channels using Cloudflare tunneling, Zoho Assist, and SSH connections configured through Visual Studio Code. Privilege escalation was also observed, with the creation of new local and domain administrator accounts. Crucially, as DART correlated activity across the environment, they discovered signs of a second, entirely unrelated threat actor operating in parallel. This secondary attacker employed different techniques, including malicious dynamic link library (DLL) sideloading and custom backdoors, which were not associated with Storm-2603. The presence of these overlapping, yet distinct, activity streams introduced an additional layer of complexity, making attribution difficult and obscuring the full scope of the intrusion. Both threat actors managed to sustain deep access, inadvertently masking each other's operations and significantly complicating detection efforts. This incident underscores the evolving nature of modern cyberattacks, where multiple adversaries can operate concurrently within a single environment. Microsoft emphasizes the critical importance of unified security visibility, advanced correlation capabilities, and coordinated incident response. Organizations must invest in connected telemetry and operational preparedness to detect adversary activity, such as credential abuse and lateral movement, earlier. This approach enables faster containment of active intrusions and limits their overall impact, strengthening resilience against future identity compromise and ransomware-driven attacks.
#incident response#threat intelligence#ransomware#cyberattack#microsoft security#hybrid cloud
Read original source