Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

Microsoft’s Detection and Response Team investigated a ransomware incident and discovered two unrelated threat actors operating simultaneously inside the same compromised environment. Storm-2603 exploited on-premises Microsoft SharePoint servers and used legitimate remote access tools to maintain persistence, while a second unidentified actor ran DLL sideloading and custom backdoors concurrently. The concurrent activity created investigative blind spots that allowed both intrusions to persist longer than a single-actor incident would have, and exposes a structural gap in how most security teams scope and triage incidents.

Author

Tech Jacks Solutions