The Containment Era is here. →Explore

Executive Summary

In June 2026, Microsoft's Detection and Response Team (DART) investigated a complex cyber intrusion involving two unrelated threat actors operating simultaneously within the same environment. The initial access was achieved through exploitation of known vulnerabilities in on-premises SharePoint servers, notably CVE-2025-49706 and CVE-2025-49704. One actor, identified as Storm-2603, utilized legitimate tools like Velociraptor to map the environment and established multiple remote access channels via Cloudflare tunneling, Zoho Assist, and SSH connections configured through Visual Studio Code. Concurrently, a second, unidentified actor employed techniques such as malicious DLL sideloading and custom backdoors, complicating detection and attribution. This dual-actor presence enabled sustained access and obfuscated the full scope of the intrusion.

This incident underscores the evolving complexity of cyber threats, where multiple actors may exploit the same vulnerabilities simultaneously, blending tactics to evade detection. It highlights the critical need for organizations to implement comprehensive patch management, enhance identity security, and maintain continuous visibility across their environments to detect and respond to such sophisticated attacks effectively.

Why This Matters Now

The convergence of multiple threat actors within a single intrusion signifies a shift in cyberattack methodologies, emphasizing the urgency for organizations to adopt integrated security measures and proactive threat detection to mitigate the risks posed by such coordinated attacks.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The attackers exploited known vulnerabilities in on-premises SharePoint servers, specifically CVE-2025-49706 and CVE-2025-49704.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust Cloud Native Security Fabric (CNSF) is pertinent to this incident as it could have significantly limited the attacker's ability to move laterally, escalate privileges, and exfiltrate data by enforcing strict segmentation and identity-based access controls.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: While initial access may still occur, CNSF would likely limit the attacker's ability to exploit this access to move laterally or escalate privileges.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: CNSF would likely constrain the attacker's ability to utilize elevated privileges to access sensitive resources or move laterally within the network.

Lateral Movement

Control: East-West Traffic Security

Mitigation: CNSF would likely limit the attacker's ability to move laterally by enforcing strict controls on east-west traffic between workloads.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: CNSF would likely detect and restrict unauthorized command and control channels by providing comprehensive visibility and control over network traffic.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: CNSF would likely limit data exfiltration attempts by enforcing strict egress policies and monitoring outbound traffic.

Impact (Mitigations)

While CNSF may not prevent the initial deployment of ransomware, it would likely limit the spread and impact by containing the attack within segmented boundaries.

Impact at a Glance

Affected Business Functions

  • Document Management
  • Collaboration Platforms
  • Internal Communications
Operational Disruption

Estimated downtime: 14 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Potential exposure of sensitive corporate documents and internal communications.

Recommended Actions

  • Implement Zero Trust Segmentation to restrict lateral movement and enforce least privilege access.
  • Deploy East-West Traffic Security controls to monitor and control internal network communications.
  • Utilize Multicloud Visibility & Control solutions to detect and respond to anomalous activities across cloud environments.
  • Enforce Egress Security & Policy Enforcement to prevent unauthorized data exfiltration.
  • Regularly update and patch systems, especially internet-facing services like SharePoint, to mitigate known vulnerabilities.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image