• 5 minuti
  • Pubblicato

Storm-2570 breaks into global networks using remote access tools

Barbara Carminati Autrice di cybersecurity e privacy QWERTYmag

Scritto da Barbara Carminati

Storm-2570 breaks into global networks using remote access tools QWERTYmag © www.qwertymag.it
Storm-2570 breaks into global networks using remote access tools © www.qwertymag.it

Storm-2570 isn't tied to just one ransomware group. It moves between Qilin, DragonForce, Anubis, and BERT, always using the same set of remote access and data theft tools. Microsoft shows how this affiliate keeps breaking in-and what defenders need to do to stop them.

MeshAgent posing as a real IT tool. Cloudflared tunnels slipping past firewalls. s5cmd quietly moving stolen data to S3 buckets controlled by attackers. These are the marks Storm-2570 leaves behind, no matter which ransomware ends up running. Microsoft Threat Intelligence has identified this affiliate as a cross-ecosystem operator. If defenders only look for the final ransomware, they risk missing the real threat hiding in their systems.

Storm-2570 has hit organizations in the United States, Canada, United Kingdom, Spain, Netherlands, and Puerto Rico. The targets range from healthcare and education to government, finance, energy, and manufacturing. Unlike groups that stick to one ransomware family, Storm-2570 goes where the money is. It uses Qilin, DragonForce, Anubis, or BERT as needed, but always falls back on the same toolkit and attack routine.

  • Reuters recently reported a sharp rise in cyberattacks on American companies. The Astrana Health breach showed how attackers pretend to be staff and use fake company numbers to get in. Astrana Health said some confidential data was accessed, but at the time, they did not expect a big financial hit. This trend shows why strong identity checks and monitoring for strange remote access are now essential. Attackers are mixing social engineering with technical tricks more than ever.

    Microsoft's research shows that Storm-2570's first step in breaking in is still unclear. But what happens next is always the same. The affiliate quickly installs remote monitoring and management (RMM) tools-MeshAgent, Atera, ScreenConnect, Splashtop, Remotely_Agent, NinjaRMM. They use discovery and lateral movement tools like NetScan, Nmap, PsExec, Impacket, NetExec, and RDP batch scripts. For stealing data, s5cmd and Rclone are their go-to tools.

    Storm-2570 non è legato a una singola famiglia di ransomware, ma agisce come affiliato trasversale, riutilizzando strumenti post-compromissione e tecniche in campagne associate a Qilin, DragonForce, Anubis e BERT. Questo conferma la necessità di concentrare la difesa non solo sul payload finale, ma sull'intera catena di attacco.

    Microsoft Security BlogThreat Intelligence Report

    MeshAgent is the key. Storm-2570 installs it again and again, often renaming files to blend in with the victim's environment. They use Base64-encoded commands to dodge detection. In one case, MeshAgent and NinjaRMM were both set up before credentials were stolen and Qilin ransomware was launched. The affiliate switches between RMM platforms, stacking Atera, Splashtop, and ScreenConnect to keep persistent, hands-on access. They use tunneling tools like ngrok and Cloudflared.exe to keep encrypted channels open, sneaking past perimeter defenses.

    Storm-2570 works directly on the keyboard. Once inside, they move fast-scanning the network, grabbing credentials with Mimikatz, LaZagne, pypykatz, and ntdsutil, then turning off security controls. They change registry settings and add Defender exclusions to weaken endpoint protection before spreading out and launching ransomware. PsExec is always in play, spreading MeshAgent and enabling RDP across machines. Impacket and NetExec help them move through SMB. For data theft, s5cmd and Rclone are used in a careful process: they collect credentials, filter for valuable files, and then send the loot to S3 buckets.

    Defending against an attacker who changes brands, not habits

    Storm-2570's methods show the real risk isn't the ransomware name-it's the affiliate's discipline. Even as the payload changes, the same remote access, credential theft, lateral movement, and exfiltration steps repeat. This matches what we saw in other ransomware cases, like our previous investigation into Settra ransomware, where remote management tools and VPN compromise let attackers sneak in.

    Microsoft's advice is clear: defenders need to move past signature-based detection and watch for behavior patterns. Turn on tamper protection. Require MFA on approved RMM systems. Set up attack surface reduction rules. Use automatic attack disruption in Microsoft Defender XDR to stop attacks in progress. Run hunting queries in Microsoft Sentinel to spot related activity. If you find unapproved RMM tools, reset credentials right away. Use threat analytics to keep up with Storm-2570's changing tactics.

    What's at stake for Italian and European companies

    For Italian and European organizations, the message is simple: ransomware affiliates like Storm-2570 don't stick to one malware family or region. They blend into normal IT work, abuse cloud storage, and switch ransomware brands as needed. This makes them a constant threat. Defenders need to stop chasing the latest ransomware name and start breaking the affiliate's playbook-spotting MeshAgent, Cloudflared tunnels, and s5cmd before the ransom note appears.

    Storm-2570's campaign is a warning for anyone who still thinks ransomware is just one big threat. The affiliate model is here for the long haul. Only those who track the operator-not just the malware-will stand a chance. Microsoft's exposure of Storm-2570's methods gives a plan for defense, but it's up to each organization to act and protect its data and reputation.

    September 2026 Patch Tuesday was Microsoft's biggest ever, with 966 to 974 CVEs fixed and two zero-day flaws actively exploited. This shows why fast patching and constant monitoring of key systems are urgent. For Italian companies, following national cybersecurity rules from agencies like the Agenzia per la Cybersicurezza Nazionale is now critical to reduce the risks from advanced affiliates like Storm-2570.

  • Articoli correlati