Microsoft has identified Storm-2570 as a ransomware affiliate using identical attack methods across multiple ransomware families, allowing defenders to spot intrusions before systems are encrypted.
Storm-2570 keeps hitting targets with the same moves. Microsoft has now mapped out the group's entire attack routine. This affiliate's habits are so predictable that defenders can spot them before any files get locked. The group's refusal to change tactics, even when switching between Qilin, DragonForce, Anubis, and BERT ransomware, is now working against them.
Victims span the United States, Canada, the United Kingdom, Spain, the Netherlands, and Puerto Rico. Storm-2570 has gone after healthcare, education, energy, and manufacturing. But the real story isn't the range of targets. It's the digital fingerprints left behind. Microsoft analysts have tracked Storm-2570 since April 2025. They see the same steps every time, no matter which ransomware family is used in the end.
Unmasking the operator behind the ransomware shuffle
Changing ransomware names is a distraction. The group's methods don't change. Once inside, Storm-2570 installs remote management tools. MeshAgent is their go-to. They often rename it to meshagent64-[organization name].exe. Other tools show up too: Atera, NinjaRMM, ScreenConnect, Splashtop, Remotely_Agent. Sometimes these are disguised to look like normal files. Tunneling tools like Cloudflared.exe and ngrok keep attacker connections hidden. These make it tough for defenders to tell attacker traffic from regular IT work.
Next comes credential theft. Storm-2570 uses network scanners and tools like Mimikatz, LaZagne, and pypykatz to grab passwords. They even use Windows' ntdsutil.exe to copy Active Directory data. This can expose credentials for the whole domain. Security controls are then weakened. Real-time protection is turned off. Antivirus exclusions are set, especially in C:\PerfLogs. Registry changes open the door for lateral movement. Remote execution tools-PsExec, Impacket, NetExec, and custom scripts-let them spread fast. These steps match what's seen with other ransomware affiliates. As reported earlier, Storm-2570's toolkit is familiar and relentless.
Microsoft's analysis of Storm-2570 is designed to detect and disrupt attacks before ransomware deployment, focusing on early indicators of compromise rather than the encryption event itself.
Data theft and the double extortion threat
Storm-2570 doesn't wait to steal data. Before any encryption, they quietly exfiltrate files. They use s5cmd.exe and Rclone to move documents, spreadsheets, databases, and archives to attacker-controlled S3 buckets or remote storage. This means even if a victim restores their systems, the risk of public data leaks remains. Microsoft hasn't shared the total number of victims or the financial fallout. It's also unclear how many attacks go from data theft to full ransomware. But the repeated use of the same scanning, remote access, and cloud upload tools lets defenders spot the pattern early-long before a ransom note appears.
Microsoft's advice is direct. Limit account privileges. Enforce strong password practices. Lock down security settings to block tampering. Multifactor authentication must be required for all remote management tools. Any unapproved installation should trigger an immediate check. Teams need to watch for odd cloud transfers and sudden remote desktop access attempts. The real chance is to catch Storm-2570 before encryption starts. Look for the mix of unexpected remote tools, credential dumping, antivirus changes, and fast outbound data flows.
Indicators and defensive priorities
Key warning signs include renamed MeshAgent files, Cloudflared.exe, ntdsutil.exe, NTDS.dit, s5cmd.exe, and scripts like rdp.bat. Watch for antivirus exclusions in C:\PerfLogs and backup files in C:\Windows\Temp\. None of these alone prove an attack. But together-especially with credential theft and remote execution-they demand urgent action.
Storm-2570's rigid habits are now its weak spot. By sticking to the same playbook, the group has given defenders a way to spot them early, no matter which ransomware name is used. Security teams should focus on the steps before encryption, not just the final payload. In ransomware defense, early detection is everything. Storm-2570's predictability is finally tipping the odds.