Full Report
Activity associated with Storm-2570, a ransomware affiliate linked to multiple ransomware payloads, illustrates how tracking and responding to ransomware attacks by payload alone can obscure the affiliates carrying out intrusions and the recurring behaviors that defenders can use to detect and disrupt them. Microsoft Threat Intelligence has observed Storm-2570 using consistent post-compromise tools and techniques across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware. Across multiple investigations, Storm-2570 has maintained largely uniform tradecraft, infrastructure overlaps, and repeated use of the same remote access and cloud exfiltration tooling despite operating across multiple ransomware ecosystems.
Analysis Summary
# Threat Actor: Storm-2570
## Attribution & Identity
* **Actor Type:** Ransomware affiliate operating within the Ransomware-as-a-Service (RaaS) model.
* **Tracked Since:** April 2025 by Microsoft Threat Intelligence.
* **Associated Groups/Ecosystems:** Linked to multiple ransomware variants including Qilin, DragonForce, Anubis, and BERT.
## Activity Summary
Storm-2570 is a persistent cybercrime affiliate that conducts network intrusions to deploy various ransomware payloads. Rather than relying on a single ransomware ecosystem, the group operates across multiple operations. Microsoft Threat Intelligence has observed the actor maintaining a highly uniform set of post-compromise tactics, techniques, and procedures (TTPs), infrastructure overlaps, and consistent remote access and cloud exfiltration tooling across distinct campaigns, regardless of the final ransomware strain deployed.
## Tactics, Techniques & Procedures
* **Initial Access & Foothold:** (Details truncated in text, but indicates standard initial access vectors leading to post-compromise activity).
* **Persistence & Remote Access:** Deploying unauthorized remote monitoring and management (RMM) tools, specifically MeshAgent / MeshCentral, to maintain access.
* **Credential Access:** Targeting credentials within the compromised environment to escalate privileges.
* **Lateral Movement:** Moving through the internal network using consistent internal tooling.
* **Defense Evasion:** Security tampering to bypass or disable endpoint protections.
* **Exfiltration:** Standardized cloud exfiltration tooling used to steal sensitive data prior to encryption.
* **Impact:** Deployment of ransomware payloads (Qilin, DragonForce, Anubis, or BERT) for double-extortion schemes.
* *Note: Specific MITRE ATT&CK IDs were not explicitly detailed in the provided text snippet, but the activities map to T1078 (Valid Accounts), T1219 (Remote Access Software), T1562.001 (Disable or Modify Tools), and T1567 (Exfiltration Over Web Service).*
## Targeting
* **Sectors:** Healthcare, Public Health, and Education.
* **Geography:** United States, Canada, United Kingdom, Spain, Netherlands, and Puerto Rico.
* **Victims:** Specific organizational names were not disclosed in the provided text.
## Tools & Infrastructure
* **Ransomware Payloads:** Qilin, DragonForce, Anubis, BERT.
* **Remote Management Tools:** MeshAgent, MeshCentral.
* **Exfiltration Support:** Unspecified cloud exfiltration tooling.
* **Infrastructure:** Overlapping Command and Control (C2) infrastructure across seemingly unrelated ransomware deployments. (Specific IPs/domains were not listed in the text, but general tracking references include social vectors like x[.]com/MsftSecIntel and bsky[.]app/profile/threatintel.microsoft.com).
## Implications
Tracking ransomware attacks solely by the payload (the encryption software) can obscure the true threat actor behind the intrusion. Storm-2570 demonstrates that affiliates frequently reuse the same infrastructure and post-compromise tradecraft across entirely different ransomware brands. Recognizing these recurring behaviors allows defenders to identify, attribute, and disrupt the intrusion during the early-to-middle stages of the attack chain before the final ransomware payload can be executed.
## Mitigations
* **Monitor Remote Admin Tools:** Implement detection mechanisms (such as the provided KQL hunting queries) to identify unauthorized installations or executions of MeshAgent, MeshCentral, and other common RMM tools.
* **Attack Chain Defense:** Focus telemetry and alerting on early-stage behaviors, such as credential dumping, lateral movement, and unauthorized data staging/exfiltration.
* **Endpoint Protection Safeguards:** Harden security controls to prevent unauthorized tampering, disabling, or exclusion configurations within endpoint detection and response (EDR) solutions.
* **Review Threat Intel:** Monitor updated tracking from intelligence feeds via standard channels such as the Microsoft Threat Intelligence Blog (aka[.]ms/threatintelblog).