Microsoft Finds Ransomware Group Using Same Attack Blueprint Across Multiple Malware Families
Microsoft says affiliate Storm-2570 reused one playbook across Qilin, DragonForce, Anubis, and BERT.
Microsoft linked ransomware affiliate Storm-2570, tracked since April 2025, to intrusions that ended with Qilin, DragonForce, Anubis, or BERT ransomware. Affected organizations span the United States, Canada, the United Kingdom, Spain, the Netherlands, and Puerto Rico, including healthcare, education, energy, and manufacturing. After access, the group installs remote-management tools such as MeshAgent, tunnels with Cloudflare Tunnel or ngrok, dumps credentials with Mimikatz, LaZagne, pypykatz, and ntdsutil, disables antivirus, and moves laterally with PsExec, Impacket, or NetExec. Before encryption it exfiltrates documents and databases to cloud storage using s5cmd and Rclone. Microsoft did not disclose initial access, victim counts, or losses.