Microsoft tracks Storm-2570’s shared ransomware tradecraft
Microsoft says affiliate Storm-2570 has reused one post-compromise playbook across Qilin, DragonForce, Anubis, and BERT since April 2025.
Microsoft Threat Intelligence says Storm-2570 is a ransomware affiliate that applies the same post-compromise tradecraft across deployments in multiple ransomware ecosystems and ransomware-as-a-service offerings. A later report says the group has been tracked since April 2025 and links it to intrusions that ended with Qilin, DragonForce, Anubis, or BERT ransomware. Affected organizations were described as spanning the United States, Canada, the United Kingdom, Spain, the Netherlands, and Puerto Rico, including healthcare, education, energy, and manufacturing. After access, the operators were said to install remote-management tools such as MeshAgent, tunnel with Cloudflare Tunnel or ngrok, dump credentials with Mimikatz, LaZagne, pypykatz, and ntdsutil, disable antivirus, and move laterally with PsExec, Impacket, or NetExec. They then copied documents and databases to cloud storage with s5cmd and Rclone before encryption. The reports do not contradict each other; the later account adds the specific families, regions, sectors, and tools, while Microsoft did not disclose initial access, victim counts, or losses.
- Microsoft Threat Intelligence identifies Storm-2570 as a ransomware affiliate that uses consistent post-compromise tradecraft across deployments and multiple ransomware-as-a-service ecosystems.
- A 25 September 2026 account says the affiliate has been tracked since April 2025 and tied to intrusions ending in Qilin, DragonForce, Anubis, or BERT ransomware.
- Named regions are the United States, Canada, the United Kingdom, Spain, the Netherlands, and Puerto Rico, covering healthcare, education, energy, and manufacturing.
- Reported post-access activity includes MeshAgent, Cloudflare Tunnel or ngrok, credential dumping with Mimikatz, LaZagne, pypykatz, and ntdsutil, antivirus disabling, and lateral movement with PsExec, Impacket, or NetExec.
- Documents and databases were exfiltrated to cloud storage with s5cmd and Rclone before encryption.
- Microsoft did not disclose initial access, victim counts, or losses.
Coverage timelineoldest first · each row is one article
- · 2d agoBeyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments
Microsoft Security Blog· 70
Microsoft Threat Intelligence has observed Storm-2570, a ransomware affiliate linked to multiple ransomware payloads, using consistent tradecraft across deployments.
- · 1d agoMicrosoft Finds Ransomware Group Using Same Attack Blueprint Across Multiple Malware Families
Cyber Security News· 74
Microsoft says affiliate Storm-2570 reused one playbook across Qilin, DragonForce, Anubis, and BERT.