HomeSecurityOut-of-date SharePoint servers opened the way for multiple cyberattacks

Out-of-date SharePoint servers opened the way for multiple cyberattacks

What started as a routine ransomware has uncovered two different attackers within the same victim’s network. The discovery came during a Microsoft Detection and Response Team (DART) investigation into the Storm-2603, a threat actor linked to ransomware development. Researchers initially believed they were tracking a single intrusion, but later identified a separate attack chain involving a different set of tools, infrastructure, and targets. It all started with unpatched SharePoint servers.

Out-of-date SharePoint servers opened the way for multiple cyberattacks

This case highlights a troubling reality: Modern attacks are not always isolated events. Sometimes they are overlapping campaigns,” Microsoft said in its latest cyberattack report. The company said that one attacker’s activity initially covered up evidence linked to the other’s attacks, complicating efforts to determine the full scope of the breach and reconstruct the timeline of the attack. “Only by correlating identity, endpoint and cloud telemetry did the full scope of the attack become clear,” the report added.

See also: Microsoft: Over 1,300 SharePoint servers vulnerable to spoofing attacks

The investigation eventually expanded beyond the initial environment and led DART to identify a second compromised organization connected to the broader attack chain.

Two attackers, one environment

SharePoint servers

The investigation began after attackers exploited vulnerabilities in on-premises SharePoint servers and installed persistence within the victim's environment.

Microsoft attributed this activity to Storm-2603, which used Cloudflare Tunnel, Zoho Assist, Visual Studio Code Remote SSH, and Velociraptor during the attack. The group also created unauthorized administrator accounts and used a vulnerable driver to disable security checks before deploying the ransomware.

As researchers attempted to piece together the timeline of the attack, they identified activity that was inconsistent with the ransomware operator's tactics, techniques, and procedures. Further analysis revealed what Microsoft described as a separate intrusion. According to the report, the second malicious actor used DLL sideloading techniques, custom backdoors, and VPN via virtual private server infrastructure and attempted to gain access to Active Directory credential databases.

See also: Microsoft fixes RCE vulnerability in SharePoint

Overlapping attacks are more common than vendors admit, said Vibhum Dubey, an independent cybersecurity researcher and red teamer.

Most incident responders are hesitant to conclude that multiple unrelated malicious actors are operating in the same environment. As a result, they can spend significant time trying to create a single kill chain from what are actually separate intrusions,” said Dubey.

SharePoint - SecNews.gr

Two teams that land on the same exposed SharePoint server are rarely coordinated. They are two separate teams scanning the same CVE feeds. The result is “same environment, zero common intent.” This overlap is also what makes such cases difficult to address, Dubey said.

See also: Microsoft OneDrive Auto-Sync exposes data in SharePoint Online

What should businesses get?

Microsoft urged organizations to prioritize updating systems exposed to the internet, especially SharePoint servers on premises, and to treat privileged identities as a primary attack surface, with tighter controls and monitoring.

The company also recommended widespread deployment of endpoint protection, telemetry centralization, restriction of remote access tools and developers , and maintaining tested incident response playbooks ready to quickly isolate compromised accounts.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS