Parallel Threat Actors Exploit Same Intrusion Undetected
This incident reveals the danger of incomplete incident response — when one attacker gains access, others may exploit the same vulnerability simultaneously or piggyback on an existing compromise. Storm-2603's use of legitimate tools like Velociraptor for persistence allowed malicious activity to blend into normal operations, delaying detection. The presence of a second, unidentified actor using DLL sideloading and custom backdoors demonstrates that organizations must assume complex, multi-party intrusions rather than single-actor scenarios. Failure to detect parallel threat activity means remediation efforts may close only one attack path while leaving others fully operational, enabling continued data exfiltration or ransomware deployment.
Tactical Insight
Immediate actions
- Conduct a full forensic sweep across all endpoints and network devices to identify ALL active threat actors before beginning remediation.
- Deploy behavioral analytics tools to flag anomalous use of legitimate administrative utilities such as Velociraptor, PsExec, or remote management software.
Detection measures
- Implement DLL sideloading detection rules in your EDR platform to catch abuse of trusted application load paths.
- Correlate logs across SIEM, EDR, and network traffic analysis tools to identify overlapping or concurrent attacker activity patterns.
- Establish baseline behavioral profiles for privileged accounts to rapidly detect privilege escalation attempts.
Long-term improvements
- Adopt a 'assume breach' incident response framework that mandates multi-actor threat hunting during every confirmed intrusion investigation.
- Apply network segmentation to limit lateral movement opportunities available to any single threat actor who gains initial access.
- Develop and regularly exercise tabletop scenarios involving simultaneous or overlapping intrusions to build investigator readiness.