Multiple Attackers Exploit Unpatched SharePoint Servers, Microsoft Reports

Multiple Attackers Exploit Unpatched SharePoint Servers, Microsoft Reports

2h ago GbhackersCsoonline 79% similarity 67.2
Share:

Article Content

Browse articles
ThreatCluster

Microsoft's DART team discovered two distinct threat actors operating simultaneously within the same victim network, complicating incident response efforts. The investigation began with ransomware activity linked to Storm-2603, which exploited vulnerabilities in on-premises SharePoint servers. The attackers created unauthorized administrator accounts and disabled security controls using a vulnerable driver. Concurrently, a second unidentified actor employed DLL sideloading techniques and attempted to access Active Directory credential databases. This overlapping activity obscured the full scope of the intrusion, complicating the reconstruction of the attack timeline. Microsoft emphasized that such simultaneous intrusions are becoming more common, as they can mask each other's activities. The investigation revealed that both actors used different tools and objectives, highlighting the complexity of modern cyberattacks. The incident underscores the need for improved detection and response strategies to handle overlapping threats.

Key Points: • Two distinct threat actors operated simultaneously within the same environment. • Storm-2603 exploited vulnerabilities in SharePoint servers to deploy ransomware. • A second unidentified actor used DLL sideloading and targeted Active Directory databases.

ThreatCluster AI

Timeline

2026-06-23
Microsoft identifies dual intrusions
DART discovered two attackers, Storm-2603 and an unknown actor, operating in the same network, complicating incident response.
Csoonline
2026-06-23
Investigation reveals ransomware deployment
Storm-2603 exploited SharePoint vulnerabilities, created unauthorized accounts, and deployed ransomware.
Gbhackers
2026-06-23
Second actor identified
The investigation uncovered a second intrusion involving DLL sideloading and attempts to access Active Directory credentials.
Csoonline

Community

Browse all →