One ransomware crew pivots between four brands with the same playbook

Microsoft says Storm-2570 swaps ransomware payloads but never swaps its tools, handing defenders a stable set of behaviors to hunt.

CSBadmin
2 Min Read

Ransomware affiliates rarely stay loyal to a single brand, and Microsoft has the intrusions to prove it. Its threat intelligence team has tracked Storm-2570 since April 2025 and watched the same crew deploy Qilin, DragonForce, Anubis and BERT payloads without changing how it breaks in.

Investigations across the United States, Canada, the United Kingdom, Spain, the Netherlands and Puerto Rico show a stable toolkit. Storm-2570 leans on remote management software including Atera, MeshAgent, ScreenConnect, Splashtop and NinjaRMM, and renames MeshAgent binaries to include the victim organization’s name so they blend in. Cloudflared.exe and ngrok then tunnel outbound access to exposed RDP services.

The tools give the crew away

From there the sequence rarely varies. NetScan, SoftPerfect and Nmap map the network. Mimikatz, LaZagne, pypykatz and ntdsutil harvest credentials from memory and from the Active Directory database. PsExec, Impacket and NetExec move laterally with host lists. Before detonating anything, the crew tampers with Microsoft Defender, adding exclusions for C:\PerfLogs and editing registry keys that govern real-time protection, then pushes data to attacker-owned S3 buckets with s5cmd or Rclone.

Where defenders can cut the chain

Microsoft’s advice follows the tooling. Turn on tamper protection so exclusions cannot be quietly added, enforce MFA on approved remote management platforms, and alert when an unapproved one appears on the network. Attack surface reduction rules that block credential theft from lsass and process creation from PsExec and WMI cut off the steps that make the rest possible.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.