logo

Microsoft Uncovers Parallel Threat Activity From Two Cyberattackers in Single Intrusion

ID: c9c828fb-9dfd-5fbb-a0f8-8aab895c251b

STIX ID: report--c9c828fb-9dfd-5fbb-a0f8-8aab895c251b

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-06-23

Date Updated: 2026-06-23

Author: Mayura Kathir

...
...

Microsoft’s incident write-up details a multi-stage intrusion that combined exploitation of internet-facing SharePoint vulnerabilities (CVE-2025-49706, CVE-2025-49704, and CVE-2025-11371) with living-off-the-land tooling and multiple remote-access channels (Velociraptor, Cloudflare tunnels, Zoho Assist, VS Code/SSH). Investigators observed parallel operators—one matching Storm-2603 ransomware activity and another using custom backdoors and DLL sideloading—highlighting deep persistence, kernel-level defense evasion, and the need for correlated identity, endpoint, and cloud telemetry to reveal the full scope.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.