MICROSOFT Threat Intelligence says Storm-2570, a ransomware affiliate tracked since April 2025, has used broadly consistent techniques while working across the Qilin, DragonForce, Anubis and BERT ransomware ecosystems. Investigated intrusions affected organisations in the United States, Canada, United Kingdom, Spain, the Netherlands and Puerto Rico, across sectors including healthcare, education, government, finance, energy, retail, IT and transport.
Microsoft says the method used to gain initial access remains unconfirmed, but observed activity after compromise followed a recurring pattern of remote access, credential theft, network discovery, lateral movement, data exfiltration, security tampering and ransomware deployment.
The affiliate repeatedly used legitimate or dual-use tools including MeshAgent, Atera, NinjaRMM, ScreenConnect, Splashtop, Remotely_Agent, PsExec, Impacket, NetExec, Nmap, Rclone and s5cmd. MeshAgent binaries were sometimes renamed with victim-specific names, while Base64-encoded commands and Cloudflare tunnels helped maintain remote access.
Storm-2570 also used ntdsutil to create Install From Media copies containing NTDS.dit and registry hives for potential offline credential extraction, modified Microsoft Defender settings and exclusions, enabled RDP and moved through networks using PsExec, SMB and administrative shares. Data was commonly staged and transferred to attacker-controlled Amazon S3 storage using s5cmd or Rclone, supporting data theft before encryption.
Microsoft recommends enabling tamper protection, strengthening MFA and controls around approved remote-management tools, applying attack-surface-reduction rules and configuring automatic attack disruption. Defender customers can also use Microsoft’s detections and hunting queries to identify PsExec activity, renamed MeshAgent deployments, credential theft, security impairment and possible exfiltration.