incident-responsevendorNewsThe Broadside1 min read

Storm-2570 runs the same playbook across four RaaS gangs

Microsoft tracked the affiliate across Qilin, DragonForce, Anubis, and BERT deployments and found the pre-ransom stage barely changes, payload choice turns out to be the least interesting part of the intrusion.


TL;DR

Microsoft Threat Intelligence has tracked Storm-2570, a ransomware affiliate active since April 2025, across four ransomware-as-a-service ecosystems: Qilin, DragonForce, Anubis, and BERT. Across multiple investigated intrusions the actor used largely uniform post-compromise tradecraft (consistent remote access tooling, lateral movement techniques, and security tampering) even as the final ransomware payload shifted. The finding underscores that payload-family indicators alone give defenders an incomplete picture; the pre-ransom stage offers more stable detection opportunities.

Microsoft's investigation found that Storm-2570 maintained consistent tooling across deployments regardless of which RaaS operation signed the checks. The commodity remote monitoring and management tools the actor favored (Atera, MeshAgent, ScreenConnect, Splashtop, and NinjaRMM) appeared across incidents tied to different ransomware families. Discovery and lateral movement followed the same pattern: NetScan, Nmap, PsExec, Impacket, NetExec, and RDP abuse showed up irrespective of the final payload.

That's the operational point Microsoft is making, and it's worth sitting with. When a victim org says "we got hit by Qilin," the natural impulse is to build detection around Qilin indicators. But Storm-2570's pre-ransom stage was nearly identical whether the payload was Qilin, DragonForce, Anubis, or BERT. Defenders hunting for unauthorized RMM installations or Impacket execution would have caught the intrusion before the ransomware ever landed.

The actor has been observed across healthcare, education, government, financial services, energy, retail, IT, food and agriculture, and critical manufacturing in the US, Canada, UK, Spain, Netherlands, and Puerto Rico. Storm-2570 appears to move between RaaS operations as opportunities arise, Microsoft describes the group as a cross-ecosystem actor rather than one loyal to a single operation.


Published ·Deep Fathom