Microsoft Uncovers Parallel Threat Activity From Two Cyberattackers in Single Intrusion
ID: c9c828fb-9dfd-5fbb-a0f8-8aab895c251b
STIX ID: report--c9c828fb-9dfd-5fbb-a0f8-8aab895c251b
Feed Name: GBHackers
Microsoft’s incident write-up details a multi-stage intrusion that combined exploitation of internet-facing SharePoint vulnerabilities (CVE-2025-49706, CVE-2025-49704, and CVE-2025-11371) with living-off-the-land tooling and multiple remote-access channels (Velociraptor, Cloudflare tunnels, Zoho Assist, VS Code/SSH). Investigators observed parallel operators—one matching Storm-2603 ransomware activity and another using custom backdoors and DLL sideloading—highlighting deep persistence, kernel-level defense evasion, and the need for correlated identity, endpoint, and cloud telemetry to reveal the full scope.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
