Decoding the world of cybersecurity

·

Ransomware affiliate moves across four criminal brands

Microsoft says one ransomware affiliate has retained largely consistent post-compromise tradecraft while deploying Qilin, DragonForce, Anubis, and BERT ransomware.

Ransomware affiliate moves across four criminal brands
Summary
  • Microsoft has tracked Storm-2570 since April 2025 across four ransomware-as-a-service ecosystems.
  • The affiliate retains similar remote-access, credential-theft, lateral-movement, and exfiltration techniques despite changing ransomware payloads.
  • Microsoft has investigated Storm-2570 intrusions in the UK, Spain, and Netherlands alongside several other countries.

A ransomware affiliate tracked by Microsoft has operated across at least four ransomware-as-a-service ecosystems while retaining much of the same post-compromise tooling and behaviour, complicating attempts to treat individual ransomware brands as separate threats.

Microsoft Threat Intelligence calls the actor Storm-2570 and says it has tracked the affiliate since April 2025. The group has been observed deploying Qilin, DragonForce, Anubis, and BERT ransomware.

Microsoft has investigated Storm-2570 intrusions affecting organisations in the UK, Spain, and Netherlands, as well as the US, Canada, and Puerto Rico. Victims have spanned healthcare, government, financial services, energy, IT, agriculture, manufacturing, transport, and other sectors.

The company has not confirmed how Storm-2570 obtains its initial foothold. Once inside an environment, however, subsequent activity has shown considerable consistency across cases involving different ransomware payloads.

Microsoft has observed remote monitoring and management tools including Atera, MeshAgent, ScreenConnect, Splashtop, and NinjaRMM. Discovery and lateral movement have involved tools including Nmap, PsExec, Impacket, NetExec, and RDP scripts.

For data collection and exfiltration, the actor has used Rclone and s5cmd. The latter is designed for Amazon S3 and compatible object storage, giving an attacker a legitimate high-speed mechanism for moving large quantities of information once access and credentials have been obtained.

The recurring behaviour is important because ransomware names can dominate incident reporting while providing an incomplete picture of who conducted an intrusion. Ransomware-as-a-service operators can supply infrastructure and payloads to affiliates that perform the hands-on compromise.

If an affiliate changes the ransomware deployed, treating each payload as an entirely separate threat can obscure recurring remote-access tooling, credential theft, network discovery, tunnelling, security-control tampering, and exfiltration that appear earlier in the attack chain.

Microsoft assesses that Storm-2570 operates across several criminal ecosystems and can shift between them as opportunities arise. That reduces the value of assuming a specific ransomware brand implies a fixed set of operators or methods.

The operational consequences are visible well before files are encrypted. Microsoft has observed the actor dumping credentials, changing Defender settings, adding exclusions, establishing tunnels, enabling RDP, and distributing remote-management tools across compromised environments.

Those stages can offer opportunities for containment regardless of which ransomware payload eventually arrives. They also show why incident response centred exclusively on encryption begins too late: by that point an attacker may already possess privileged credentials, persistence, remote access, and copies of sensitive data.

Legitimate administrative software complicates detection further. Remote-management agents, tunnelling services, storage utilities, and native Windows tools all have ordinary uses. The signal often lies in unexpected deployment, account context, execution sequence, or destination rather than the presence of a particular binary.

Microsoft’s findings do not mean Qilin, DragonForce, Anubis, and BERT are one operation. The research instead describes one tracked affiliate operating across those ecosystems.

That distinction reflects ransomware’s increasingly modular structure. Payload operators, affiliates, initial-access specialists, negotiators, and infrastructure providers can move independently. Following the behaviour of the people conducting an intrusion can provide continuity even when the ransomware name changes.

×