Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments

Executive Summary

Microsoft Security reports that the ransomware affiliate Storm-2570 consistently applies the same post‑compromise tools and techniques across multiple ransomware families—Qilin, DragonForce, Anubis, and BERT. The blog outlines the tradecraft, including shared command‑and‑control infrastructure, lateral movement tactics, and data exfiltration patterns, and offers defenders actionable guidance to detect and disrupt the activity before ransomware is deployed.


Intelligence Metadata - Source Publisher: Microsoft Security - Published Date: 2026-09-24T16:00:00+00:00 - Category: threat-intel

Original Description: Storm-2570 is a ransomware affiliate that uses consistent post-compromise tools and techniques across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware, and provides guidance to help defenders detect and disrupt this activity before ransomware deployment. The post Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments appeared first on Microsoft Security Blog.

"In all chaos there is a cosmos, in all disorder a secret order."

— Carl Jung
Source: Microsoft Security