SharePoint ransomware attacks have revealed a new challenge for incident responders after Microsoft uncovered two unrelated threat groups operating inside the same compromised environment at the same time. The investigation shows that modern cyberattacks can overlap rather than occur as isolated incidents, making detection and containment far more difficult. Microsoft is urging organizations to strengthen patching, identity protection, and continuous monitoring to reduce the risk of similar compromises.

Microsoft Discovered Parallel Intrusions

Microsoft’s Detection and Response Team (DART) investigated a ransomware incident involving vulnerable on-premises SharePoint servers. During the investigation, researchers found signs that attackers had moved beyond the original victim’s environment into a second organization.

After notifying the second company, Microsoft confirmed that it had also been compromised by the ransomware group tracked as Storm-2603.

As investigators gathered additional evidence, Microsoft Threat Intelligence identified another surprise. A second, unrelated threat actor had been operating inside the same environment at the same time.

Researchers explained that the campaigns ran in parallel rather than one after the other. Without combining identity, endpoint, and cloud telemetry, security teams might have viewed the activity as a single attack and overlooked the broader compromise.

SharePoint Vulnerabilities Opened the Door

According to Microsoft, Storm-2603 has targeted on-premises SharePoint servers since mid-2025 by exploiting publicly disclosed vulnerabilities.

Internet-facing SharePoint deployments remain attractive targets because they often contain valuable business data and can provide an entry point into wider corporate networks.

Microsoft stressed that organizations should quickly patch known vulnerabilities, particularly those affecting externally accessible systems, to reduce exposure to ransomware groups.

Second Threat Actor Used Different Techniques

While Storm-2603 focused on ransomware activity, the second attacker relied on different methods to maintain long-term access.

Investigators found evidence of Dynamic Link Library (DLL) sideloading, a technique that allows malicious code to execute through trusted software. Attackers frequently use this method to deploy payloads, install backdoors, or remain hidden inside compromised environments.

The presence of two independent threat groups demonstrates that cybercriminals can exploit the same vulnerable organization simultaneously without coordinating their activities.

Although Microsoft did not disclose the financial impact of the incident, the company noted that overlapping attacks significantly complicate incident response and recovery efforts.

Microsoft Calls for Stronger Defensive Strategies

The investigation reinforces Microsoft’s recommendation that organizations adopt layered security rather than relying on a single defensive control.

The company advises organizations to prioritize rapid patching of internet-facing systems and address known exploitable vulnerabilities as quickly as possible. Microsoft also recommends protecting privileged identities, deploying endpoint protection across the environment before an incident occurs, and maintaining continuous monitoring instead of relying on temporary security tools introduced during an active breach.

Combining telemetry across endpoints, identities, cloud services, and on-premises infrastructure allows defenders to detect complex attack patterns that isolated security tools may miss.

Overlapping Campaigns Are Becoming More Common

Microsoft believes this case reflects an important shift in today’s threat landscape. Organizations can no longer assume that one incident involves only one attacker.

As multiple threat actors increasingly exploit the same vulnerabilities, security teams must investigate suspicious activity with a broader perspective. Parallel intrusions can introduce different objectives, techniques, and persistence mechanisms that require separate containment and remediation efforts.

Understanding the complete scope of an incident has become just as important as stopping the initial attack.

Conclusion

The SharePoint ransomware investigation demonstrates how modern cyberattacks continue growing in complexity. Microsoft’s discovery of two unrelated threat groups operating simultaneously highlights the need for coordinated visibility across cloud, endpoint, and identity systems. Organizations that patch vulnerabilities quickly, strengthen identity security, and maintain continuous monitoring will be better prepared to detect overlapping campaigns before attackers establish long-term access.


0 responses to “SharePoint Ransomware Attacks Expose Parallel Threat Campaigns”