Double Trouble: Two Unrelated Attacks Thrive on Unpatched SharePoint
Microsoft DART untangles dual intrusions on the same server, each attacker accidentally covering the other's tracks.

Key points
- Two unrelated threat actors operated inside the same victim network simultaneously, each obscuring the other's activity.
- Storm-2603 exploited unpatched on-premises SharePoint servers, deployed remote-access tools, created rogue admin accounts, and dropped ransomware.
- A second actor used DLL sideloading (hijacking a legitimate process to load a malicious library), custom backdoors, and VPN tunnels to target credential databases.
- Microsoft DART identified a second compromised organisation connected to the same Storm-2603 activity.
- An unpatched internet-facing server was the single root cause that let both actors walk in.
How did two attackers end up in the same network?
A ransomware investigation by the Microsoft Detection and Response Team (DART) turned into something rarer: a double intrusion. Storm-2603 got in first through unpatched on-premises SharePoint servers, deploying Cloudflare Tunnel, Zoho Assist, and Velociraptor, creating unauthorised admin accounts, then disabling security controls before dropping ransomware. Investigators expected one kill chain. They found two.
The second actor's fingerprints were different: DLL sideloading, bespoke backdoors, VPN access through virtual private server infrastructure, and attempts against Active Directory credential databases. Neither group knew about the other. Each set of activity masked the other's, making the timeline nearly impossible to read at first.
Should you worry about two attackers at once?
Vibhum Dubey, an independent red teamer, says this kind of collision is under-reported. "Most incident responders hesitate to conclude that multiple unrelated actors are operating in the same environment, so they may spend considerable time trying to build a single coherent kill chain from what are actually separate intrusions," he told CSO Online. Two groups hitting the same exposed box, he said, is rarely coordinated: it's both teams scanning the same vulnerability feeds and getting lucky in the same window.
Containment is where the complexity bites. Evict one group and rotate credentials, and the second actor, never fully scoped, notices the disruption and goes loud. DART avoided that by separating the artifact clusters from each actor before touching anything. Dubey called that discipline "what made the difference."
We've tracked SharePoint's recurring role as an entry point across 17 stories in the last 90 days, and the pattern is consistent: exposure to the internet plus a slow patch cycle equals a crowded hallway.
What should defenders do?
Microsoft's recommendations are straightforward. Patch internet-facing systems promptly. Treat privileged identities as a primary attack surface with tighter monitoring. Deploy endpoint protection broadly, centralise telemetry from identities, endpoints, and cloud services, and keep a tested incident response playbook ready to isolate accounts fast.
Dubey puts it more bluntly. "An internet-facing box sat unpatched long enough for more than one actor to walk through the door," he told CSO Online. Everything that followed was downstream of that one failure.
The judgement worth carrying away from this case: the forensic complexity was real, but the cause was ordinary. Two sophisticated attack chains, plenty of custom tooling, and a second victim organisation discovered mid-investigation, all because nobody applied a patch. The attackers weren't clever. The open door was.



