Executive Summary
In June 2026, Microsoft's Detection and Response Team (DART) investigated a complex cyber intrusion involving two unrelated threat actors operating simultaneously within the same environment. The initial access was achieved through exploitation of known vulnerabilities in on-premises SharePoint servers, notably CVE-2025-49706 and CVE-2025-49704. One actor, identified as Storm-2603, utilized legitimate tools like Velociraptor to map the environment and established multiple remote access channels via Cloudflare tunneling, Zoho Assist, and SSH connections configured through Visual Studio Code. Concurrently, a second, unidentified actor employed techniques such as malicious DLL sideloading and custom backdoors, complicating detection and attribution. This dual-actor presence enabled sustained access and obfuscated the full scope of the intrusion.
This incident underscores the evolving complexity of cyber threats, where multiple actors may exploit the same vulnerabilities simultaneously, blending tactics to evade detection. It highlights the critical need for organizations to implement comprehensive patch management, enhance identity security, and maintain continuous visibility across their environments to detect and respond to such sophisticated attacks effectively.
Why This Matters Now
The convergence of multiple threat actors within a single intrusion signifies a shift in cyberattack methodologies, emphasizing the urgency for organizations to adopt integrated security measures and proactive threat detection to mitigate the risks posed by such coordinated attacks.
Attack Path Analysis
The attack began with Storm-2603 exploiting vulnerabilities in on-premises SharePoint servers to gain initial access. They escalated privileges by deploying Velociraptor with SYSTEM-level rights and creating new administrator accounts. Utilizing tools like PsExec and Impacket, they moved laterally across the network. For command and control, they established remote access channels through Cloudflare tunneling, Zoho Assist, and SSH via Visual Studio Code. Data exfiltration was achieved by copying sensitive files to external servers. The impact culminated in the deployment of Warlock ransomware, encrypting critical data and disrupting operations.
Kill Chain Progression
Initial Compromise
Description
Storm-2603 exploited vulnerabilities in on-premises SharePoint servers to gain unauthorized access.
Related CVEs
CVE-2025-49704
CVSS 8.8A code injection vulnerability in Microsoft SharePoint Server allows authenticated remote attackers to execute arbitrary code.
Affected Products:
Microsoft SharePoint Server – 2013, 2016, 2019, Subscription Edition
Exploit Status:
exploited in the wildCVE-2025-53770
CVSS 8A remote code execution vulnerability in Microsoft SharePoint Server allows authenticated attackers to execute arbitrary code.
Affected Products:
Microsoft SharePoint Server – 2016, 2019, Subscription Edition
Exploit Status:
exploited in the wildCVE-2025-21400
CVSS 8A remote code execution vulnerability in Microsoft SharePoint Server allows authenticated attackers to execute arbitrary code.
Affected Products:
Microsoft SharePoint Server – 2016, 2019, Subscription Edition
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Valid Accounts
Remote Access Software
Create or Modify System Process: Windows Service
Hijack Execution Flow: DLL Side-Loading
Process Injection: Dynamic-link Library Injection
Exploitation for Privilege Escalation
Impair Defenses: Disable or Modify Tools
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
Critical exposure to ransomware targeting SharePoint servers, vulnerable to DLL sideloading, lateral movement, and multi-actor intrusions requiring enhanced segmentation.
Financial Services
High-value targets for parallel threat actors exploiting legitimate tools like Velociraptor, requiring strict compliance with PCI and egress controls.
Health Care / Life Sciences
HIPAA-regulated environments face severe risks from credential abuse and data exfiltration through compromised SharePoint systems and tunneling techniques.
Government Administration
Mission-critical systems vulnerable to sophisticated multi-stage intrusions exploiting administrative tools, demanding zero-trust segmentation and continuous monitoring capabilities.
Sources
- One intrusion, two cyberattackers: Uncovering parallel threat activityhttps://www.microsoft.com/en-us/security/blog/2026/06/22/one-intrusion-two-cyberattackers-uncovering-parallel-threat-activity/Verified
- CVE-2025-49704 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2025-49704Verified
- CVE-2025-53770 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2025-53770Verified
- CVE-2025-21400 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2025-21400Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust Cloud Native Security Fabric (CNSF) is pertinent to this incident as it could have significantly limited the attacker's ability to move laterally, escalate privileges, and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While initial access may still occur, CNSF would likely limit the attacker's ability to exploit this access to move laterally or escalate privileges.
Control: Zero Trust Segmentation
Mitigation: CNSF would likely constrain the attacker's ability to utilize elevated privileges to access sensitive resources or move laterally within the network.
Control: East-West Traffic Security
Mitigation: CNSF would likely limit the attacker's ability to move laterally by enforcing strict controls on east-west traffic between workloads.
Control: Multicloud Visibility & Control
Mitigation: CNSF would likely detect and restrict unauthorized command and control channels by providing comprehensive visibility and control over network traffic.
Control: Egress Security & Policy Enforcement
Mitigation: CNSF would likely limit data exfiltration attempts by enforcing strict egress policies and monitoring outbound traffic.
While CNSF may not prevent the initial deployment of ransomware, it would likely limit the spread and impact by containing the attack within segmented boundaries.
Impact at a Glance
Affected Business Functions
- Document Management
- Collaboration Platforms
- Internal Communications
Estimated downtime: 14 days
Estimated loss: $500,000
Potential exposure of sensitive corporate documents and internal communications.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement and enforce least privilege access.
- • Deploy East-West Traffic Security controls to monitor and control internal network communications.
- • Utilize Multicloud Visibility & Control solutions to detect and respond to anomalous activities across cloud environments.
- • Enforce Egress Security & Policy Enforcement to prevent unauthorized data exfiltration.
- • Regularly update and patch systems, especially internet-facing services like SharePoint, to mitigate known vulnerabilities.



