Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments
Brief
In this article
- Who is Storm-2570?
- Storm-2570 attack chain: From initial foothold to impact
- What Storm-2570 activity means for defenders
- Mitigation and protection guidance
- Microsoft Defender detections
- Hunting queries
Activity associated with Storm-2570, a ransomware Microsoft Threat Intelligence has observed Storm-2570 using consistent post-compromise tools and techniques across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware.
Across multiple investigations, Storm-2570 has maintained largely uniform tradecraft, infrastructure overlaps, and repeated use of the same remote access and cloud exfiltration tooling despite operating across multiple ransomware ecosystems.
These findings reinforce the value of examining threat actor behavior across the attack chain rather than treating each ransomware payload as an isolated activity set.
