security: One intrusion, two cyberattackers: Uncovering parallel threat activity
Microsoft Security Blog
2026-06-22
Microsoft describes a ransomware case where two threat actors operated in parallel during the same intrusion, using overlapping tactics and evasion methods. The report emphasizes that isolated telemetry can miss complex attacks when activity from multiple actors is blended together.