incident-responsevendorNewsThe Broadside1 min read

Microsoft finds two actors inside one SharePoint intrusion

Attribution gets less useful when two intruders share the same blast radius and both hide behind legitimate administrative tooling.


TL;DR

Microsoft DART says a ransomware investigation found two unrelated threat actors operating in the same hybrid environment. Storm-2603 had targeted on-premises SharePoint servers since mid-2025, used legitimate tools including Velociraptor, Cloudflare tunneling, Zoho Assist and SSH through Visual Studio Code, and created local and domain administrator accounts. A second actor used DLL sideloading and custom backdoors. For defenders, the point is not the label; it is separating overlapping activity before containment decisions get contaminated.

Microsoft’s useful finding is also the part that makes incident response uglier: the investigation did not resolve into one clean campaign with one operator, one toolchain and one set of motives. DART says it began as a ransomware investigation and ended with evidence of two unrelated actors working in parallel inside the same environment, with Storm-2603 activity around on-premises SharePoint and a second stream involving malicious DLL sideloading and custom backdoors.

The operational lesson is narrower than the marketing wrapper. Microsoft says Storm-2603 had been targeting on-premises SharePoint servers since mid-2025, exploiting known vulnerabilities and probing for files such as win.ini and web.config; in this case, exploitation through that separate path was not confirmed. Once inside, the actor allegedly used Velociraptor with SYSTEM-level privileges, Cloudflare tunneling, Zoho Assist and SSH connections configured through Visual Studio Code, then created local and domain administrator accounts and used a vulnerable driver to interfere with protections.

That is not exotic malware theater. It is the familiar problem of legitimate administration tools doing illegitimate work, with a second actor adding enough unrelated tradecraft to make correlation harder. For teams running on-premises SharePoint, the Monday work is basic but not small: separate actor timelines, validate administrator account creation, hunt for remote access channels that look like support tooling, and avoid treating attribution as containment. The wrong single-campaign story can leave the second foothold intact.


Published ·Deep Fathom