Microsoft probes rare dual-operator ransomware hit tied to SharePoint

Modern intrusions can overlap and demand coordinated detection and response

Must Read

- Advertisement -
- Advertisement -
  • Storm‑2603 has targeted on‑premises SharePoint servers since mid‑2025 by exploiting known vulnerabilities.
  • The second actor left indicators of Dynamic Link Library sideloading—tactics often used to masquerade as trusted software, execute payloads, establish backdoors, and maintain persistence.

Microsoft’s Incident Response team uncovered a ransomware case in which two unrelated threat actors operated simultaneously inside victim environments, underscoring how modern intrusions can overlap and demand coordinated detection and response, the company said in a new DART report.

Investigators traced the activity to on‑premises SharePoint servers targeted via publicly disclosed vulnerabilities. The intrusion blended classic ransomware techniques with additional tradecraft designed to gain deep, persistent access across identities, endpoints, and cloud resources.

After initial findings indicated lateral movement into a second organization, Microsoft notified the entity, which confirmed compromise by the same ransomware activity attributed to Storm‑2603. A joint review with Microsoft Threat Intelligence then revealed a second, separate threat actor acting in parallel.

“Two distinct threat activity streams were operating in parallel, rather than sequentially,” Microsoft’s researchers said, noting that only by correlating identity, endpoint, and cloud telemetry did the full scope become clear.

According to Microsoft, Storm‑2603 has targeted on‑premises SharePoint servers since mid‑2025 by exploiting known vulnerabilities. The second actor left indicators of Dynamic Link Library (DLL) sideloading—tactics often used to masquerade as trusted software, execute payloads, establish backdoors, and maintain persistence.

The report did not detail financial losses.

Microsoft urged organisations to tighten defenses, including:

  • Prioritizing rapid patching of internet‑facing systems and known exploitable vulnerabilities
  • Treating high‑privilege identities as critical attack surfaces
  • Ensuring endpoint protection is fully deployed before incidents occur
  • Avoiding gaps from point‑in‑time tool deployment through continuous monitoring

The company framed the case as a warning that overlapping campaigns are becoming more common, requiring integrated visibility and coordinated response across the enterprise.

- Advertisement -

Latest News

Google to retire assistant on mobile devices starting September 4

Gemini, Google's newer AI-powered assistant, to become the default across all supported platforms.

WebKit flaw exposes real IP addresses of iOS and Mac users

If you require genuine IP anonymity on iOS or macOS, a device-level VPN is the only reliable option.

Ola Electric and Axis Energy ink 20 GWh battery storage deal

Ola Electric MoU is an early and emphatic demonstration of the demand Mahashakti can capture from the outset
- Advertisement -
- Advertisement -

More Articles

- Advertisement -