Select a theme from the list.
Insights

From our experts

Latest
Unpatched OnePlus Chain Gives Permissionless Android Apps Root ControlMacSync Turns Public iCloud Calendars Into a Hidden Malware Delivery ChannelStorm-2570 Changes Ransomware Brands but Keeps the Same Attack PlaybookExploited F5 OAuth Flaw Opens a Direct Route Into Access InfrastructureAI Attack Crews Turn Online Stores Into Industrial Card-Skimming TargetsMicrosoft Builds an Agentic Command Center for the Modern SOCOT Segmentation Study Finds Critical Devices Sharing Networks With Everyday ITBifrost Gateway Flaw Opens AI Infrastructure to Unauthenticated Command ExecutionTrustSink Turns a Rogue MFA Provider Into a Silent Password CollectorColorado Water Attacks Show How Small Utilities Become Physical TargetsJade Sleet Turns Developer Interviews Into a Doorway to IT ProvidersStolen Ribon App Credentials Open BigCommerce Stores to Data TheftUnpatched OnePlus Chain Gives Permissionless Android Apps Root ControlMacSync Turns Public iCloud Calendars Into a Hidden Malware Delivery ChannelStorm-2570 Changes Ransomware Brands but Keeps the Same Attack PlaybookExploited F5 OAuth Flaw Opens a Direct Route Into Access InfrastructureAI Attack Crews Turn Online Stores Into Industrial Card-Skimming TargetsMicrosoft Builds an Agentic Command Center for the Modern SOCOT Segmentation Study Finds Critical Devices Sharing Networks With Everyday ITBifrost Gateway Flaw Opens AI Infrastructure to Unauthenticated Command ExecutionTrustSink Turns a Rogue MFA Provider Into a Silent Password CollectorColorado Water Attacks Show How Small Utilities Become Physical TargetsJade Sleet Turns Developer Interviews Into a Doorway to IT ProvidersStolen Ribon App Credentials Open BigCommerce Stores to Data Theft
Security Insight

Storm-2570 Changes Ransomware Brands but Keeps the Same Attack Playbook

Storm-2570 Changes Ransomware Brands but Keeps the Same Attack Playbook
Photo by Rafael Minguet Delgado on Pexels

Microsoft has linked a single ransomware affiliate to intrusions involving Qilin, DragonForce, Anubis and BERT payloads. Although the final ransomware changes, Storm-2570 repeatedly uses the same remote-management tools, credential theft techniques, tunneling services and cloud utilities. The findings suggest defenders should track attacker behavior rather than relying primarily on malware family names.

News Date: 2026-09-24

Microsoft Threat Intelligence has documented a ransomware affiliate that demonstrates why malware branding is becoming an unreliable way to classify modern intrusions. Tracked as Storm-2570, the operator has participated in attacks involving Qilin, DragonForce, Anubis and BERT ransomware while maintaining a largely consistent collection of tools and techniques.

One Operator, Several Ransomware Ecosystems

Storm-2570 has been tracked since April 2025 and has affected organizations across sectors including healthcare, education, government, financial services, energy, retail, manufacturing and transportation. Microsoft says the initial access method remains uncertain, but the activity observed after compromise follows a recognizable pattern.

The affiliate installs legitimate remote-monitoring products such as Atera, MeshAgent, ScreenConnect and Splashtop. It may rename agents to resemble software belonging to the victim organization, making unauthorized services less conspicuous during a casual review.

The attackers also use Cloudflare Tunnel, ngrok and similar utilities to maintain outbound connections or expose Remote Desktop services. Discovery and lateral movement involve familiar administration and penetration-testing tools, including Nmap, PsExec, Impacket and NetExec.

Credentials and Cloud Storage Become Key Targets

After mapping the environment, Storm-2570 attempts to obtain privileged credentials through tools such as Mimikatz, LaZagne and pypykatz. Microsoft also observed the use of the legitimate Windows ntdsutil utility to prepare Active Directory database material for offline password-hash extraction.

For data theft, the group favors Rclone and s5cmd, which can move large collections of business files into attacker-controlled cloud storage. This supports double-extortion operations in which information is stolen before systems are encrypted.

Defensive Priorities

  • Inventory approved remote-management software and investigate unknown agents immediately.
  • Require multifactor authentication for administrative and RMM accounts.
  • Protect endpoint security settings against local modification.
  • Monitor unusual Cloudflare Tunnel, ngrok, Rclone and s5cmd activity.
  • Restrict PsExec, RDP and administrative shares wherever practical.

In my view, the central lesson is that ransomware response should begin before the encryptor appears. A new ransom note may represent an old operator using familiar infrastructure. Organizations that correlate remote-access installation, credential dumping, security tampering and cloud exfiltration can identify the intrusion while there is still time to contain it.

Talk to our team →

Latest

Unpatched OnePlus Chain Gives Permissionless Android Apps Root ControlSep 25, 2026MacSync Turns Public iCloud Calendars Into a Hidden Malware Delivery ChannelSep 25, 2026Storm-2570 Changes Ransomware Brands but Keeps the Same Attack PlaybookSep 25, 2026Exploited F5 OAuth Flaw Opens a Direct Route Into Access InfrastructureSep 24, 2026AI Attack Crews Turn Online Stores Into Industrial Card-Skimming TargetsSep 24, 2026Microsoft Builds an Agentic Command Center for the Modern SOCSep 24, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication4Global CMS Exploitation Wave Plants Webshells on Business Websites5Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards6Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path