Storm-2570 Uses Four Ransomware Brands—and the Same Access Tools

Brendan Smith
Brendan Smith - Cybersecurity Analyst
6 Min Read
One hand holds four masks, representing Storm-2570 using multiple ransomware brands.
Different ransomware names can conceal a recurring operator.

Changing the ransomware name does not necessarily mean changing the attacker. Microsoft’s September 24 investigation links Storm-2570 to Qilin, DragonForce, Anubis and BERT deployments, while finding a recurring set of remote-access tools, credential theft and cloud uploads underneath those different labels.

For a business investigating an unexpected remote-management service, the useful part of the report comes before the ransom note. The group repeatedly builds ways to return, spreads access and steals data. Waiting to identify the eventual encryptor can leave that earlier activity unexamined. Microsoft has tracked the affiliate since April 2025; its initial entry method remains unconfirmed.

Different payloads, overlapping operations

An affiliate carries out intrusions using ransomware supplied by an operation. Microsoft assesses that Storm-2570 works across several such ecosystems rather than staying with one. Its published timeline includes overlapping deployment windows, so this is more complicated than a simple rebranding from one name to the next.

Microsoft timeline of Storm-2570 ransomware deployments, showing overlapping use of BERT, Qilin, DragonForce and Anubis.
Observed deployment windows overlap: the affiliate did not simply replace one ransomware name with the next. Source: Microsoft Threat Intelligence.

The timeline is useful because the ransom note describes the payload encountered in one incident, not the full history of the person or group operating it. Microsoft’s investigation connects activity across cases through repeated behavior and infrastructure. It does not establish that every Qilin, DragonForce, Anubis or BERT attack belongs to Storm-2570.

A remote agent dressed in the victim’s name

MeshAgent appears repeatedly in the investigated intrusions. In some deployments, the attacker renamed its executable to include the compromised organization’s name. That is a revealing disguise: a file that appears tailored to the business can look more credible than an unfamiliar program with a random name.

Remote-management software has legitimate uses, so the name alone is a poor verdict. The stronger questions are who installed it, whether the deployment was authorized, which management server it contacts and what it launched afterward. An organization’s name in a filename answers none of those questions.

Microsoft also observed multiple access tools within the same intrusion. In one case, MeshAgent was followed by a persistent Cloudflare Tunnel service running as LocalSystem. That gives the attacker another route from inside the network. Removing one remote agent therefore need not remove every access path; an outbound tunnel also deserves investigation even when incoming connections are restricted.

A separate Settra investigation involving MeshAgent illustrates the same need to examine surrounding evidence. Shared administrative software does not, by itself, connect two campaigns or identify their operator.

The escalation from one computer to domain credentials

The report describes Storm-2570 using the Windows utility ntdsutil to obtain Active Directory database material. In this context, the significant fact is the level of access: Microsoft says the activity indicates high privileges on a domain controller. The concern has moved beyond an unwanted application on one workstation to credentials that may affect other systems.

That distinction changes the response. Deleting a suspicious executable does not revoke credentials already copied elsewhere. Responders need to establish which accounts and machines were reached and coordinate credential recovery with containment, rather than treat an apparently clean desktop as the end of the incident.

Across observed cases, the attacker also interfered with Defender settings, including real-time monitoring and an exclusion for C:\PerfLogs. A restored setting is worth checking against its change history: who altered it, from which process and with which account? The sequence can explain why a later payload had room to run.

Cloud uploads can precede visible damage

Microsoft found Storm-2570 using s5cmd and Rclone for data theft. In several intrusions, files were copied to attacker-controlled S3 buckets. These are ordinary transfer tools used for an unauthorized destination; their presence needs context, not an automatic assumption that every cloud backup is malicious.

The practical consequence is easy to miss: intact, readable files do not rule out a confidentiality incident. A company may stop encryption after data has left. Conversely, finding a transfer utility is not proof of a completed upload. Destination records, process activity and available transfer logs are needed to determine what actually happened.

Investigate the access, not only the final name

Microsoft recommends controlling approved remote-management deployments, using multifactor authentication where supported, protecting security settings against tampering and investigating accounts used to install unauthorized agents. For an active incident, preserve relevant endpoint, identity and remote-management records while isolating affected systems through the organization’s response process.

If an unfamiliar executable needs an additional file assessment, Gridinsoft’s file checker can help identify it; do not upload confidential material or treat a file verdict as a complete network investigation.

Storm-2570’s useful signature is the relationship between actions: unexpected access, expanding privilege, weakened protection and data movement. The ransomware brand may change. Those earlier decisions are where defenders can still interrupt the intrusion.

References

  1. Microsoft Threat Intelligence. Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments. Microsoft Security Blog, September 24, 2026.
Share This Article
Cybersecurity Analyst
Follow:
Brendan Smith has spent over 15 years knee-deep in cybersecurity, chasing down malware from the gritty reverse-engineering of old-school trojans all the way to wrangling full-blown incident responses for small-to-medium businesses that couldn’t afford a full-blown breach. Over at Gridinsoft, he’s the guy piecing together those double-checked guides on nasty stuff like AsyncRAT, a remote access tool used in malware campaigns—helping readers make sense of the threat and work through cleanup without the extra headache.
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?