Microsoft Tracks Storm-2570 Ransomware Affiliate Behind Qilin, DragonForce, Anubis, and BERT Deployments

Microsoft Tracks Storm-2570 Ransomware Affiliate Behind (TL-2026-2729) is a high-severity ransomware operation, first published 2026-09-27. It is attributed to Storm-2570 with medium confidence, maps to 17 MITRE ATT&CK techniques (T1003.001, T1003.003, T1018), and is covered by 9 detection rules and 19 indicators of compromise.

Key facts for TL-2026-2729

Threat ID
TL-2026-2729
Severity
HIGH
Status
ACTIVE
Category
RANSOMWARE
First published
2026-09-27
Last reviewed
2026-09-27
Attribution
Storm-2570
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
health, education, government administration, financial services, energy, manufacturing, retail, information technology
Target regions
North America, Europe
Detection rules
9
Indicators of compromise
19

Malware and tooling in Microsoft Tracks Storm-2570 Ransomware Affiliate Behind

Malware and tooling: AgendaCrypt, Anubis Ransomware, Bert, DragonForce, MimiKatz, anubis, Atera, CloudFlare Tunnel, Impacket - S0357, LaZagne - S0349, MeshAgent / MeshCentral, MeshCentral

Microsoft Threat Intelligence has tracked Storm-2570, a cross-ecosystem ransomware affiliate, since April 2025 as it rotates between Qilin, DragonForce, Anubis, and BERT ransomware payloads while reusing an identical pre-encryption tradecraft chain. The actor has hit healthcare, education, government, financial, energy, and manufacturing organizations across the US, Canada, UK, Spain, Netherlands, and Puerto Rico, and Microsoft's guidance emphasizes detecting the shared toolchain rather than any single ransomware family.

How Microsoft Tracks Storm-2570 Ransomware Affiliate Behind works

Storm-2570 is a ransomware affiliate that Microsoft Threat Intelligence has followed since April 2025 across intrusions ultimately culminating in four different ransomware payloads: Qilin, DragonForce, Anubis, and BERT. Rather than being tied to a single ransomware-as-a-service (RaaS) brand, Storm-2570 behaves as a cross-ecosystem operator that shifts between RaaS programs as opportunities arise, retaining the flexibility to deploy whichever payload is most advantageous for a given payout while keeping its intrusion tradecraft essentially constant.

Microsoft states that the actor's initial access method remains unconfirmed, but from the point of foothold onward the group follows a highly consistent playbook. Discovery is performed with NetScan, SoftPerfect Network Scanner Portable, Nmap, and native Windows commands to map reachable hosts, shares, and high-value targets. Credential access relies on Mimikatz, LaZagne, and pypykatz for in-memory credential theft, paired with ntdsutil.exe to create an Install-From-Media (IFM) backup of the Active Directory database (NTDS.dit) staged under C:\Windows\Temp.

For persistence and hands-on-keyboard access, Storm-2570 deploys a wide bench of legitimate remote monitoring and management (RMM) tools -- MeshAgent/MeshCentral (its most consistent tool, frequently renamed to match the victim organization, e.g. meshagent64-[organization].exe), Atera, ScreenConnect, NinjaRMM, Splashtop, and Remotely_Agent -- alongside Cloudflare Tunnel (cloudflared.exe, run as a persistent LocalSystem service) and ngrok to expose RDP on TCP 3389. Defense evasion centers on tampering with Microsoft Defender: disabling real-time monitoring, adding an exclusion for C:\PerfLogs, and modifying DisableAntiSpyware/DisableRealtimeMonitoring registry values and WinDefend service behavior. Lateral movement is carried out with PsExec (driven by host lists such as @ip.txt), Impacket, and NetExec over SMB, plus batch scripts (rdp.bat) that enable Remote Desktop and open the corresponding firewall rule.

Before encryption, the group exfiltrates data using s5cmd (staged with hardcoded AWS access keys to push documents, spreadsheets, databases, mail files, images, and archives to attacker-controlled S3 buckets) and Rclone for real-time cloud synchronization, supporting a double-extortion model. Only after staging is complete does Storm-2570 hand off to whichever ransomware payload -- Qilin, DragonForce, Anubis, or BERT -- is deployed for that engagement, each of which independently operates a RaaS/cartel affiliate program (Qilin: 80-85% affiliate payouts plus a 'Call Lawyer' pressure feature and a Tor/clearnet WikiLeaksV2 leak site; DragonForce: a self-declared 'cartel' since March 2025 offering white-label branding and 80% payouts to affiliates). Microsoft's guidance to defenders is to hunt the consistent pre-encryption toolchain -- rogue RMM agents, NTDS.dit IFM extraction, Defender tampering, PsExec-driven lateral movement, and S3/Rclone exfiltration -- rather than waiting to catch the final, rotating ransomware family.

MITRE ATT&CK techniques used in TL-2026-2729

Credential Access

T1003.001 LSASS Memory; T1003.003 NTDS

Discovery

T1018 Remote System Discovery; T1033 System Owner/User Discovery; T1087.001 Local Account; T1087.002 Domain Account; T1135 Network Share Discovery

Lateral Movement

T1021.001 Remote Desktop Protocol; T1021.002 SMB/Windows Admin Shares; T1570 Lateral Tool Transfer

Defense Evasion

T1027 Obfuscated Files or Information

Execution

T1059.001 PowerShell

Command and Control

T1219 Remote Access Tools; T1572 Protocol Tunneling

Exfiltration

T1537 Transfer Data to Cloud Account; T1567.002 Exfiltration to Cloud Storage

defense-impairment

T1685 Disable or Modify Tools

Remediation for Microsoft Tracks Storm-2570 Ransomware Affiliate Behind

Immediate actions

  • Enable Microsoft Defender tamper protection tenant-wide to block registry-based disabling of real-time monitoring and DisableAntiSpyware modification
  • Identify and remove any RMM software (MeshAgent/MeshCentral, Atera, ScreenConnect, NinjaRMM, Splashtop, Remotely_Agent) not explicitly sanctioned by IT, and reset credentials for any RMM service accounts found with unauthorized installations
  • Block or alert on Cloudflare Tunnel (cloudflared.exe) and ngrok binaries and outbound tunnel establishment from endpoints that should not be running them
  • Restrict and monitor ntdsutil.exe usage; alert on Install-From-Media (IFM) backup creation of NTDS.dit outside scheduled AD maintenance

Workarounds

  • Alert on renamed MeshAgent binaries matching organizational-name patterns (meshagent64-[organization].exe) at process-creation time
  • Monitor for Defender exclusion additions targeting C:\PerfLogs and other non-standard paths
  • Alert on outbound S3 API traffic via s5cmd or bulk Rclone sync jobs originating from endpoints that have no legitimate cloud-storage business need

Longer-term hardening

  • Enforce MFA for all approved RMM systems and remote administration tooling
  • Deploy Microsoft Defender Attack Surface Reduction rules to block PsExec/WMI-based process creation and enable ransomware protection features
  • Enable automatic attack disruption in Microsoft Defender XDR to contain hands-on-keyboard ransomware activity
  • Apply the DisableLocalAdminMerge GPO policy to prevent local Defender exclusion-list tampering from propagating via Group Policy
  • Segment and monitor SMB/administrative-share traffic to detect Impacket- and NetExec-driven lateral movement

Timeline of Microsoft Tracks Storm-2570 Ransomware Affiliate Behind

  • Qilin ransomware operators (one of Storm-2570's rotating payloads) extend double-extortion exposure by launching WikiLeaksV2, a clearnet mirror of their Tor-based leak site, in addition to the existing dark-web site.
  • DragonForce (another of Storm-2570's rotating payloads) publicly rebrands as a ransomware 'cartel,' shifting to a distributed affiliate model offering white-label encryptors, customizable branding, and 80% payouts.
  • Microsoft Threat Intelligence begins tracking Storm-2570 as a distinct ransomware affiliate, observing a consistent pre-encryption tradecraft chain across multiple investigated intrusions.
  • Between January and May 2026, Qilin (one of Storm-2570's deployed families) is linked to at least 557 separate ransomware incidents, making it the most active RaaS operation of the period.
  • Qilin's leak site is observed listing 2,302 total publicly claimed victims, including 107 added in the preceding 30 days.
  • Microsoft publishes 'Beyond the ransomware: Tracking Storm-2570's consistent tradecraft across deployments,' detailing the shared RMM abuse, NTDS.dit theft, Defender tampering, PsExec-driven lateral movement, and S3/Rclone exfiltration tradecraft observed across Storm-2570's Qilin, DragonForce, Anubis, and BERT deployments, along with Defender detection names and KQL hunting queries.
  • Cyber Security News, Cyberpress, and other outlets republish and summarize Microsoft's Storm-2570 findings, extending public awareness of the shared tradecraft to detect across all four ransomware families.

Sources cited for Microsoft Tracks Storm-2570 Ransomware Affiliate Behind

More in ransomware

Detection coverage for TL-2026-2729

As of 2026-09-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2729 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats