News Date: 2026-09-24
Microsoft Threat Intelligence has documented a ransomware affiliate that demonstrates why malware branding is becoming an unreliable way to classify modern intrusions. Tracked as Storm-2570, the operator has participated in attacks involving Qilin, DragonForce, Anubis and BERT ransomware while maintaining a largely consistent collection of tools and techniques.
One Operator, Several Ransomware Ecosystems
Storm-2570 has been tracked since April 2025 and has affected organizations across sectors including healthcare, education, government, financial services, energy, retail, manufacturing and transportation. Microsoft says the initial access method remains uncertain, but the activity observed after compromise follows a recognizable pattern.
The affiliate installs legitimate remote-monitoring products such as Atera, MeshAgent, ScreenConnect and Splashtop. It may rename agents to resemble software belonging to the victim organization, making unauthorized services less conspicuous during a casual review.
The attackers also use Cloudflare Tunnel, ngrok and similar utilities to maintain outbound connections or expose Remote Desktop services. Discovery and lateral movement involve familiar administration and penetration-testing tools, including Nmap, PsExec, Impacket and NetExec.
Credentials and Cloud Storage Become Key Targets
After mapping the environment, Storm-2570 attempts to obtain privileged credentials through tools such as Mimikatz, LaZagne and pypykatz. Microsoft also observed the use of the legitimate Windows ntdsutil utility to prepare Active Directory database material for offline password-hash extraction.
For data theft, the group favors Rclone and s5cmd, which can move large collections of business files into attacker-controlled cloud storage. This supports double-extortion operations in which information is stolen before systems are encrypted.
Defensive Priorities
- Inventory approved remote-management software and investigate unknown agents immediately.
- Require multifactor authentication for administrative and RMM accounts.
- Protect endpoint security settings against local modification.
- Monitor unusual Cloudflare Tunnel, ngrok, Rclone and s5cmd activity.
- Restrict PsExec, RDP and administrative shares wherever practical.
In my view, the central lesson is that ransomware response should begin before the encryptor appears. A new ransom note may represent an old operator using familiar infrastructure. Organizations that correlate remote-access installation, credential dumping, security tampering and cloud exfiltration can identify the intrusion while there is still time to contain it.
