Double Trouble: Two Unrelated Attacks Thrive on Unpatched SharePoint

Microsoft DART uncovers dual intrusions on same server, complicating response efforts.

ThreatVectr Newsdesk· 2 min read
Double Trouble: Two Unrelated Attacks Thrive on Unpatched SharePoint
Share

A routine investigation into a ransomware breach uncovered a rare spectacle: two unrelated attackers operating simultaneously within the same victim network. The Microsoft Detection and Response Team (DART), probing a threat actor named Storm-2603 linked to ransomware, stumbled upon another distinct attack chain, each side inadvertently obscuring the other's digital tracks.

The confusion began with vulnerabilities exploited in on-premises SharePoint servers, a common weak link. Storm-2603 took advantage of these, deploying tools like Cloudflare Tunnel and Zoho Assist, setting up unauthorized admin accounts, and dropping ransomware. But as investigators pieced together the timeline, they unearthed activity inconsistent with Storm-2603's known tactics. This led to the identification of a second actor using DLL sideloading, custom backdoors, and VPN access, aiming to infiltrate Active Directory credential databases.

Vibhum Dubey, a cybersecurity researcher, weighs in: "Overlapping intrusions occur more often than acknowledged. Incident responders usually hesitate to conclude multiple actors are involved, often trying to create a single narrative from separate incidents." He adds, "Two groups exploiting the same vulnerability isn't a coordinated effort, just a case of lucky timing."

This overlap complicated the response. Microsoft DART expanded their investigation beyond the original network, discovering a second organization afflicted by the same Storm-2603 activity. The dual presence of attackers in the same environment illustrated the challenge of containment; removing one could inadvertently alert the other. Dubey notes that only by correctly identifying and separating the artifacts of each threat actor could DART enact an effective response.

Microsoft's report recommends that organizations patch internet-facing systems like SharePoint promptly, tighten controls around privileged identities, and ensure robust endpoint protection. Dubey asserts the breach’s root cause was simple: "An unpatched server allowed multiple actors entry. Everything after was just fallout from that oversight."

In the end, the dual attack was a reminder of the complexity of modern cyber threats, where multiple actors can collide on the same digital stage.

© 2026 Threat Vectr