Storm-2570 Ransomware Tradecraft: Key Defender Insights
Summary
Microsoft Threat Intelligence says Storm-2570 is a cross-ecosystem ransomware affiliate using consistent tools and techniques across Qilin, DragonForce, Anubis, and BERT deployments. The report matters because defenders can improve detection and disruption by tracking recurring tradecraft such as RMM abuse, credential theft, tunneling, and cloud exfiltration instead of focusing only on the final ransomware payload.
Introduction
Microsoft’s latest threat intelligence on Storm-2570 highlights an important shift for defenders: ransomware investigations cannot stop at the payload name. The same affiliate may work across multiple ransomware-as-a-service ecosystems while reusing similar post-compromise techniques, giving security teams a better chance to detect attacks earlier in the chain.
What’s new
Microsoft has linked Storm-2570 activity to multiple ransomware families, including Qilin, DragonForce, Anubis, and BERT. Despite the different payloads, the actor has shown consistent tradecraft across incidents.
Recurring tools and behaviors
- Remote access and RMM abuse: Atera, MeshAgent, ScreenConnect, Splashtop, Remotely_Agent, and NinjaRMM
- Discovery and lateral movement: NetScan, Nmap, PsExec, Impacket, NetExec, and RDP batch scripts
- Credential access: Mimikatz, LaZagne, pypykatz, and ntdsutil for NTDS.dit dumping
- Tunneling and persistence: Cloudflared.exe and ngrok to maintain outbound access
- Data exfiltration: Rclone and s5cmd for collection and transfer
Microsoft also observed frequent use of MeshAgent and MeshCentral as operational bridges between initial access and later actions such as account manipulation, reconnaissance, security tampering, and ransomware deployment. In some cases, the actor renamed binaries and services to match the victim environment, making malicious tooling appear more legitimate.
Why this matters for IT and security teams
The key takeaway is that payload-based detection alone can miss the bigger picture. If teams only hunt for a specific ransomware family, they may overlook the affiliate’s earlier activity, where there is more opportunity to contain the intrusion.
For administrators and defenders, the report reinforces the need to monitor:
- Unexpected RMM tool installation or execution
- New tunnel services running as LocalSystem
- Credential dumping behavior against Active Directory
- Internal scanning and rapid remote command execution
- Cloud exfiltration utilities appearing on servers or endpoints
Recommended next steps
- Review whether approved RMM tools are tightly controlled and alert on unapproved deployments.
- Audit systems for Cloudflared, ngrok, Rclone, s5cmd, and renamed MeshAgent binaries.
- Strengthen detections for credential dumping and ntdsutil misuse.
- Use Microsoft Defender detections and hunting guidance from the Microsoft Threat Intelligence post.
- Investigate activity chains, not just ransomware payload names, to connect related intrusions sooner.
Storm-2570 is a reminder that consistent attacker behavior often matters more than the final malware family. Organizations that baseline admin tools, monitor abuse patterns, and hunt across the full attack chain will be better positioned to disrupt ransomware before encryption begins.
Need help with Security?
Our experts can help you implement and optimize your Microsoft solutions.
Talk to an ExpertStay updated on Microsoft technologies