Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Exploit Tools for Network Persistence

Hackers Exploit Tools for Network Persistence

Posted on June 23, 2026 By CWS

In a startling discovery, security researchers investigating a ransomware incident uncovered two distinct threat actors operating within the same compromised network. This revelation highlighted a sophisticated intrusion involving multiple tools and strategies for sustained access.

Complex Intrusion with Multiple Tools

The investigation, which began as a single intrusion, soon revealed a complex operation. Multiple remote access tools, tunneling software, and legitimate administrative utilities were leveraged for long-term persistence in the target’s infrastructure. These activities were centered on on-premises SharePoint servers, which had been under attack since mid-2025 by a threat group known as Storm-2603. By exploiting known vulnerabilities, they sought additional entry points.

Researchers noted requests for sensitive files such as win.ini and web.config, indicative of reconnaissance for local file inclusion weaknesses. However, the full exploitation of this vector was not confirmed during the initial investigation.

Coordinated Efforts and Overlapping Campaigns

Microsoft’s analysts, through their Detection and Response Team (DART), mapped out the full scope of the campaign. They identified the use of multiple tools to maintain access, escalate privileges, and remain hidden within the network for extended periods. This layering of access, utilizing both familiar and trusted tools, obscured malicious activities as routine system administration.

Interestingly, another unrelated group was found to be operating simultaneously in the same environment. This group used different techniques, such as malicious DLL sideloading and custom backdoors, complicating attribution and detection efforts.

Tools Leveraged for Persistence

Storm-2603 deployed Velociraptor, a trusted open-source forensic tool, with SYSTEM-level privileges to map the environment. Its legitimate use by security teams enabled the attackers to camouflage their presence effectively. Additionally, Cloudflare tunnels were configured to route traffic through a trusted service, bypassing traditional network monitoring.

Other tools like Zoho Assist and Visual Studio Code’s SSH feature were employed to establish multiple access channels, ensuring persistence even if one method was discovered. Privilege escalation followed, with new administrator accounts created to secure long-term control.

Microsoft’s DART team contained the intrusion by activating a structured response, correlating data across impacted systems, and conducting regular briefings with the organization to ensure a coordinated containment strategy.

Enhancing Network Defense Strategies

This case underscores the lengths to which threat actors will go to maintain network access. The simultaneous presence of multiple groups complicates signal clarity and attribution, challenging traditional detection methods. Microsoft advises organizations to prioritize patching internet-facing systems and strengthen identity security, as credential misuse was pivotal in this case.

Furthermore, deploying endpoint protection widely, centralizing telemetry retention, and maintaining tested incident response playbooks are critical. Monitoring the use of remote access and tunneling tools is essential, as legitimate software like Velociraptor, VS Code, and Zoho Assist can be exploited by attackers to move stealthily within compromised networks.

Stay updated on the latest in cybersecurity by following us on Google News, LinkedIn, and X. Set Cyber Security News as a preferred source in Google for more instant updates.

Cyber Security News Tags:Cloudflare tunnels, Cybersecurity, Hackers, Microsoft DART, network security, remote access tools, system vulnerabilities, Velociraptor, VS Code SSH, Zoho Assist

Post navigation

Previous Post: Samsung KNOX Vulnerability Exposed Millions of Devices
Next Post: GitHub Enhances Security by Blocking Risky Pwn Requests

Related Posts

BoryptGrab Malware Targets Users via Fake GitHub Projects BoryptGrab Malware Targets Users via Fake GitHub Projects Cyber Security News
Network Communication Blocker Tool That Neutralizes EDR/AV Network Communication Blocker Tool That Neutralizes EDR/AV Cyber Security News
New Kali Tool llm-tools-nmap Uses Nmap For Network Scanning Capabilities New Kali Tool llm-tools-nmap Uses Nmap For Network Scanning Capabilities Cyber Security News
New Eleven11bot Hacked 86,000 IP Cameras for Massive DDoS Attack New Eleven11bot Hacked 86,000 IP Cameras for Massive DDoS Attack Cyber Security News
Lazarus Hackers Weaponized 234 Packages Across npm and PyPI to Infect Developers Lazarus Hackers Weaponized 234 Packages Across npm and PyPI to Infect Developers Cyber Security News
HSBC India Enforces Uppercase-Only Passwords HSBC India Enforces Uppercase-Only Passwords Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Dragos Launches EmberAI for Enhanced OT Cybersecurity
  • AI Skill Bypasses Security, Affects Thousands
  • Critical Dify Vulnerabilities Risk AI Data Leakage
  • FFmpeg Vulnerability Enables Remote Code Execution
  • LastPass Data Breach Exposes Customer Information via Klue

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Dragos Launches EmberAI for Enhanced OT Cybersecurity
  • AI Skill Bypasses Security, Affects Thousands
  • Critical Dify Vulnerabilities Risk AI Data Leakage
  • FFmpeg Vulnerability Enables Remote Code Execution
  • LastPass Data Breach Exposes Customer Information via Klue

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark