← Back to feed
Breaches & RansomwareEmerging1 sourceSep 24, 2026 · 16:00via Microsoft Security Blog

Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments

Brief

In this article

  • Who is Storm-2570?
  • Storm-2570 attack chain: From initial foothold to impact
  • What Storm-2570 activity means for defenders
  • Mitigation and protection guidance
  • Microsoft Defender detections
  • Hunting queries

Activity associated with Storm-2570, a ransomware Microsoft Threat Intelligence has observed Storm-2570 using consistent post-compromise tools and techniques across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware.

Across multiple investigations, Storm-2570 has maintained largely uniform tradecraft, infrastructure overlaps, and repeated use of the same remote access and cloud exfiltration tooling despite operating across multiple ransomware ecosystems.

These findings reinforce the value of examining threat actor behavior across the attack chain rather than treating each ransomware payload as an isolated activity set.

Read more on Microsoft Security Blog→