Microsoft analyzes Storm-2570 across ransomware ecosystems
Microsoft described the Storm-2570 actor, linking it to the deployment of four ransomware families and a repeated post-compromise process.

Microsoft Threat Intelligence published an analysis of the actor known as Storm-2570 on September 24, 2026. According to the company, the actor had been observed deploying Qilin, DragonForce, Anubis and BERT ransomware since April 2025. The report does not describe a new vulnerability or confirmed exploitation of a specific security flaw.
The research focuses on a recurring process after an environment is compromised. Microsoft says similar techniques appeared across multiple ransomware brands. For defenders, the name of the ransomware used may therefore not be the only decisive factor; the set of tools and techniques used before systems are encrypted may also matter.
Storm-2570 and the recurring attack process
Microsoft describes a sequence of steps that includes the use of remote management tools, network reconnaissance, credential theft, lateral movement, data exfiltration and the subsequent deployment of ransomware. This process may give security teams an opportunity to detect the attack before its final stage.
The tools observed in connection with the activity include:
- MeshAgent, Atera, ScreenConnect and Splashtop,
- PsExec, Impacket and NetExec,
- Rclone and s5cmd.
Microsoft also recorded tampering with Microsoft Defender protections. This included disabling real-time monitoring and adding exclusions. These actions may reduce security software’s ability to detect the attacker’s further activity.
Why monitoring only the ransomware family is not enough
In this case, Microsoft highlights a consistent operational process attributed to one actor across multiple ransomware families.
For security teams, activity correlation is relevant, including combinations of remote administration tools, network reconnaissance, domain credential use, lateral movement and exfiltration to cloud storage. Microsoft provided detection and mitigation recommendations focused on these stages.
Organizations should pay particular attention to controlling the use of remote administration tools, protecting against tampering with security products and limiting lateral movement within the network. Monitoring should also check for combinations involving MeshAgent or other RMM solutions, Cloudflare Tunnel or ngrok tunneling services, PsExec and s5cmd or Rclone tools.
Open questions surrounding attribution
Microsoft did not confirm the initial vector through which Storm-2570 gains access to targeted networks. The full number of victims and the extent of financial damage that could be attributed to this actor have also not been publicly documented.
The attribution of specific incidents and ransomware deployments is an assessment by Microsoft Threat Intelligence. Independent public confirmation of all the stated attributions was not available. Another point to monitor will be whether security vendors or authorities publish their own indicators of compromise or additional findings about the actor’s activity.
Microsoft’s analysis expands the detection context for cases in which the ransomware brands used may change while the operator’s process remains similar. For defenders, the technical indicators and behavior in the compromised environment described in the report are therefore especially important.
Sources
- Microsoft Security Blog – Primary research by Microsoft Threat Intelligence describing the attribution of Storm-2570, observed TTPs, ransomware families used, detections and recommended mitigations.
Verified and updated: 09/25/2026 06:26



