Storm-2570 Switches Between 4 Ransomware Brands but Reuses the Same Attack Trail

Microsoft says Storm-2570 has deployed Qilin, DragonForce, Anubis, and BERT while reusing the same post-compromise tools and techniques.

Sep 28, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Storm-2570 keeps changing ransomware brands, but its post-compromise playbook stays remarkably consistent. Microsoft Threat Intelligence says the affiliate has deployed Qilin, DragonForce, Anubis, and BERT while repeatedly using many of the same tools and techniques.

Microsoft has tracked Storm-2570 since April 2025 across intrusions in the United States, Canada, the United Kingdom, Spain, the Netherlands, and Puerto Rico. Affected sectors include healthcare, government, financial services, energy, IT, critical manufacturing, and transportation.

In its Sept. 24 Storm-2570 analysis, Microsoft said defenders may miss recurring affiliate behavior when they classify incidents mainly by the ransomware payload. Remote access, credential theft, lateral movement, security tampering, and data exfiltration can provide signals before ransomware deployment.

Storm-2570 repeats its post-compromise playbook

Microsoft has not confirmed how Storm-2570 first gains access to victim networks. After compromise, the actor has repeatedly used remote monitoring and management (RMM) software, tunneling utilities, credential-access tools, and lateral-movement techniques.

Observed RMM tools include Atera, MeshAgent, ScreenConnect, Splashtop, Remotely_Agent, and NinjaRMM. Microsoft also documented ngrok and Cloudflare Tunnel being used to expose Remote Desktop Protocol (RDP) services or maintain outbound access.

Because administrators also rely on RMM tools, their presence alone does not establish malicious activity. A separate RMM phishing campaign spanning 46 countries showed how attackers can turn legitimate remote-access software into an entry point. Microsoft found Storm-2570 renaming MeshAgent binaries with victim-themed filenames, including meshagent64-[organization name].exe, to make them appear more legitimate.

For credential access, the affiliate has used Mimikatz, LaZagne, pypykatz, and the Windows ntdsutil utility. Microsoft observed ntdsutil staging NTDS.dit and registry hive data from Active Directory domain controllers, which can support offline extraction of credential hashes. Recent attacks against forgotten Microsoft 365 service accounts also show how poorly protected identities can preserve attacker access.

Advertisement

Storm-2570 has used PsExec, Impacket, NetExec, and RDP scripts for lateral movement. Microsoft also observed Defender tampering in Qilin, DragonForce, and Anubis incidents, including disabled real-time monitoring, added exclusions, and registry changes.

Qilin also appeared in a separate Cisco FMC intrusion campaign in which attackers compromised firewall-management infrastructure before moving deeper into victim networks.

Data theft can precede encryption. Microsoft said s5cmd was the exfiltration tool it observed most often, moving business files to attacker-controlled S3-compatible storage, while Rclone appeared in other intrusions.

Detection can start before ransomware deployment

Microsoft’s recommendations, combined with the CISA #StopRansomware Guide, point to six practical controls:

  • Restrict RMM and remote access by approving specific tools and access paths, enforcing MFA, reviewing RMM activity, and resetting credentials tied to unauthorized deployments.
  • Limit lateral movement through network segmentation, least privilege, hardened privileged accounts, and tighter controls on unnecessary remote administration.
  • Harden endpoint and identity defenses with tamper protection, credential safeguards, relevant attack surface reduction rules, and automatic attack disruption where available.
  • Centralize security monitoring across endpoint, identity, RMM, network, and cloud logs to correlate suspicious activity across the intrusion chain.
  • Monitor exfiltration and protect recovery by alerting on unusual cloud transfers and maintaining isolated, encrypted, regularly tested backups.
  • Test and rehearse incident response plans using ransomware and RMM-abuse scenarios covering isolation, evidence preservation, credential resets, threat hunting, communications, and recovery.

Microsoft also published hunting queries for PsExec-based remote execution and renamed MeshAgent binaries and services. Microsoft still has not identified Storm-2570’s initial-access method, but its recurring post-compromise behavior gives defenders multiple opportunities to hunt and contain the affiliate before ransomware deployment.

Read more: Agentic ransomware is bringing greater automation and adaptability to enterprise ransomware attacks.


eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.