VYPR
researchPublished Sep 24, 2026· 1 source

Storm-2570 Affiliate Leverages Consistent Tradecraft Across Multiple Ransomware Families

Microsoft Threat Intelligence tracks Storm-2570, a ransomware affiliate linked to Qilin, DragonForce, Anubis, and BERT, demonstrating consistent post-compromise techniques regardless of the final ransomware payload.

Microsoft Threat Intelligence has identified a persistent ransomware affiliate, tracked as Storm-2570, that exhibits remarkably consistent tradecraft across multiple ransomware-as-a-service (RaaS) operations. This affiliate has been observed working with distinct ransomware families including Qilin, DragonForce, Anubis, and BERT, indicating a flexible and opportunistic approach to cybercrime. By maintaining uniform post-compromise techniques, infrastructure overlaps, and repeated use of specific remote access and cloud exfiltration tools, Storm-2570 provides defenders with a unique opportunity to disrupt attacks before the final ransomware payload is deployed, irrespective of the chosen ransomware family.

Storm-2570 has been active since April 2025, impacting a wide array of sectors across North America and Europe, including healthcare, education, government, financial services, and critical manufacturing. Unlike threat actors dedicated to a single RaaS ecosystem, Storm-2570 appears to operate as a cross-ecosystem entity, shifting between operations to maximize payout opportunities. This adaptability means organizations could face the same actor and intrusion methods even when different ransomware strains are deployed, underscoring the importance of tracking the affiliate's behavior rather than solely focusing on the ransomware payload.

While the initial access vector for Storm-2570 remains unconfirmed, their post-compromise activity typically involves the deployment of commodity tools for remote management, discovery, and data exfiltration. Key tools frequently observed include remote monitoring and management (RMM) solutions such as Atera, MeshAgent, ScreenConnect, and NinjaRMM, alongside discovery and lateral movement utilities like Nmap, PsExec, Impacket, and NetExec. Data collection and exfiltration are often facilitated by tools like s5cmd and Rclone.

MeshAgent, in particular, has been a recurring tool in Storm-2570's arsenal, often used as an operational bridge after initial access to expand control, execute commands, and prepare for later-stage actions. The affiliate demonstrates a degree of sophistication by tailoring MeshAgent deployments to the compromised environment, frequently renaming binaries and services with victim-themed names to evade detection. Base64 encoding is also employed to obfuscate commands, further complicating analysis.

Beyond MeshAgent, Storm-2570 utilizes a diverse set of remote access tools, often deploying multiple platforms within a single intrusion. This rotation among commercially available RMMs, remote desktop components, and tunneling utilities highlights their adaptability and resourcefulness. For instance, Atera has been observed being used to install agents, followed by activity progressing to credential dumping and ransomware deployment.

The consistent tradecraft employed by Storm-2570, including their reliance on specific RMMs and exfiltration tools, provides valuable indicators of compromise (IOCs) for defenders. By analyzing these recurring behaviors, security teams can identify and disrupt the affiliate's operations at earlier stages, potentially preventing the final ransomware encryption and data destruction.

Microsoft recommends that organizations focus on hardening their defenses against these common post-compromise techniques. This includes implementing robust endpoint detection and response (EDR) solutions, monitoring for the deployment of unauthorized RMM tools, and enforcing strict access controls. Understanding the TTPs of affiliates like Storm-2570 is crucial for developing effective, proactive defense strategies against the evolving ransomware threat landscape.

Microsoft Defender provides detections for the tools and techniques associated with Storm-2570. Additionally, hunting queries can be developed to identify suspicious activity related to the observed TTPs, enabling security teams to proactively hunt for and mitigate threats before significant damage occurs.

Synthesized by Vypr AI