Microsoft tracks Storm-2570’s consistent tactics across multiple ransomware deployments

Published:

Microsoft has identified Storm-2570, a ransomware affiliate, as a significant threat actor employing consistent tactics across various ransomware deployments, including Qilin, DragonForce, Anubis, and BERT. This tracking reveals that the group maintains uniform tradecraft and infrastructure, complicating detection efforts for defenders. The findings emphasize the importance of analyzing threat actor behavior beyond individual ransomware payloads to enhance cybersecurity responses.

Middle East Relevance

While the report does not specify direct incidents involving Storm-2570 in the UAE or broader Middle East region, the group’s operational patterns and tools could pose risks to organizations in these areas, particularly those utilizing similar remote management and cloud services. The adaptability of Storm-2570 across different ransomware ecosystems suggests that regional entities could encounter similar tactics if they are targeted.

Key Facts

  • Storm-2570 has been tracked by Microsoft since April 2025.
  • The group operates across multiple ransomware-as-a-service ecosystems, affecting sectors such as healthcare, education, and government.
  • Common tools used by Storm-2570 include remote monitoring and management (RMM) tools like MeshAgent and Atera.
  • Storm-2570 employs credential access techniques using tools like Mimikatz and ntdsutil for Active Directory credential dumping.
  • Data exfiltration is often conducted using s5cmd and Rclone, facilitating double-extortion tactics.

Technical Context

Storm-2570’s methodology involves a series of post-compromise tactics that include the use of remote access tools, credential harvesting, and data exfiltration. The group frequently utilizes RMM tools such as MeshAgent, which allows for remote administration and command execution. Their operations often involve creating persistent access paths using tunneling utilities like Cloudflared.exe, enabling covert remote access even after initial detection attempts.

Risk and Decision

Organizations should recognize the potential for Storm-2570’s tactics to impact their cybersecurity posture. The group’s ability to shift between different ransomware payloads while maintaining consistent operational methods necessitates a proactive approach to cybersecurity. Companies should assess their defenses against the specific tools and techniques employed by Storm-2570 to mitigate risks effectively.

Defensive Guidance

To defend against Storm-2570’s tactics, Microsoft recommends the following actions:

  • Implement tenant-wide tamper protection to prevent attackers from disabling security services.
  • Enforce multi-factor authentication (MFA) for approved RMM systems and reset passwords for any unapproved installations.
  • Utilize Microsoft Defender XDR to configure automatic attack disruption, limiting the impact of ongoing attacks.
  • Follow best practices for credential hygiene and limit lateral movement using the principle of least privilege.

Source and Evidence

This report is based on findings from the Microsoft Security Blog, detailing the activities and tactics of Storm-2570 as of September 2026. The insights provided are drawn from threat intelligence observations and do not constitute independent verification of incidents or claims.

CWME will continue tracking regional implications as more verified information becomes available.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

CrowdStrike recognized as leader in Forrester Wave for proactive security platforms

CrowdStrike has been recognized as a Leader in The Forrester Wave: Proactive Security Platforms, Q3 2026, achieving the highest score in the Strategy category...

Citrix NetScaler ADC and Gateway products affected by multiple critical CVEs

Citrix has disclosed multiple critical vulnerabilities affecting its NetScaler ADC and Gateway products, with at least two of these vulnerabilities, CVE-2026-88771 and CVE-2026-88772, reportedly...

AI is transforming product team dynamics, says Muhammad Danish

Artificial intelligence (AI) is fundamentally transforming product team dynamics, according to Muhammad Danish, Senior Director of Product Design at Emirates NBD. He highlights that...

Old-school credit card scams persist as new threats emerge

Despite the rise of sophisticated digital fraud, traditional credit card scams remain a significant threat. Recent incidents in Europe and the U.S. highlight the...