Microsoft Storm-2570: same post-compromise blueprint across Qilin / DragonForce / Anubis / BERT ransomware
Microsoft Threat Intelligence (24 September 2026) details Storm-2570, a ransomware affiliate observed since April 2025 whose final payload rotates among Qilin, DragonForce, Anubis, and BERT while post-compromise tradecraft stays consistent. Victims span US, Canada, UK, Spain, Netherlands and Puerto Rico across healthcare, education, energy and manufacturing. After access (initial vector not established in the post), operators install remote-management tools (MeshAgent/MeshCentral often renamed; also Atera, NinjaRMM, ScreenConnect, Splashtop, Remotely_Agent), tunnel with Cloudflare Tunnel or ngrok, harvest credentials (Mimikatz, LaZagne, pypykatz, AD database copy), disable AV/real-time protection, move laterally via PsExec/Impacket/NetExec/RDP, then exfiltrate and encrypt. Microsoft urges defenders to hunt affiliate behaviours before ransomware deployment rather than by payload name alone. Primary: Microsoft Security Blog.
- Product
- n/a (ransomware affiliate tradecraft; Microsoft Defender detections referenced in post)
- Versions
- n/a
- Exploited in Australia?
- unknown
- Patch to
- Hunt MeshAgent/unexpected RMM, Cloudflare Tunnel/ngrok, credential dumpers, and AV tampering before encryption; apply Microsoft’s Defender detections and hunting queries from the blog; treat payload brand changes as the same affiliate when tradecraft matches.
Primary: Microsoft — Beyond the ransomware: Tracking Storm-2570 (24 Sep 2026) · Vendor: Microsoft Threat Intelligence · Cyber Security News — Storm-2570 amplify (25 Sep 2026)
