2026-09-29HIGHMicrosoft: the same toolkit rides into victims regardless of which ransomware brand signs the note
Anubis (ransomware-as-a-service)
actor · actor:anubis-raas single-source
Ransomware-as-a-service operation named by GuidePoint Security as one of the programmes whose victims were approached by the Ransom Busters persona (GuidePoint Security, 2026-08-18). Distinct from the unrelated Anubis Android banking-trojan family.
Coverage
2
first 2026-08-20 → last 2026-09-29
Latest activity
2026-09-29
Microsoft: the same toolkit rides into victims regardless of which ransomware brand signs the note
Peak priority
high
1 high · 1 notable
Targets
public-sector
sectors: public-sector, healthcare, education · regions: us, europe
Sources cited
3
3 hosts
2026-08-202 appearances2026-09-29
Defender insights
What each entry about Anubis (ransomware-as-a-service) tells a defender to do, newest first.
Triage
Triage
Relationships explore in graph
Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.
collaborates with
- Ransom Bustersnamed by GuidePoint alongside DragonForce and Settra as a programme whose incidents carried the same outreach
- Storm-2570Microsoft: Storm-2570 operates as an affiliate deploying Anubis ransomware as one of its RaaS-brand payloads.
Story timeline
- 2026-09-29Storm-2570: a ransomware affiliate reuses a consistent commodity RMM/tunnelling/credential-theft toolkit across four separate RaaS brands, with government agencies among its confirmed victims
- 2026-08-20"Ransom Busters" emails ransomware victims before their incident is public, offering to delete the stolen data for a fee, and the tooling says it is the same affiliate who took it
Hunting pivots
ATT&CK techniques (14 across 9 tactics)
14 techniques observed across 2 entries about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- ExecutionCommand and Scripting Interpreter: PowerShell · System Services: Service Execution
- PersistenceCreate Account: Local Account
- Defense ImpairmentDisable or Modify Tools
- Credential AccessOS Credential Dumping: LSASS Memory · OS Credential Dumping: NTDS · Credentials from Password Stores
- DiscoveryNetwork Service Discovery
- Lateral MovementRemote Services: Remote Desktop Protocol · Lateral Tool Transfer
- Command and ControlRemote Access Tools · Protocol Tunneling
- ExfiltrationExfiltration Over Web Service: Exfiltration to Cloud Storage
- ImpactFinancial Theft
Execution TA0002
T1059.001Command and Scripting Interpreter: PowerShell×1
Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the <code>Start-Process</code> cmdlet which can be used to run an executable and the <code>Invoke-Command</code> cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems).
Evidence: 2026-08-20/ransom-busters-rogue-affiliate-fake-recovery-firm · ATT&CK page ↗
T1569.002System Services: Service Execution×1
Adversaries may abuse the Windows service control manager to execute malicious commands or payloads. The Windows service control manager (<code>services.exe</code>) is an interface to manage and manipulate services. The service control manager is accessible to users via GUI components as well as system utilities such as <code>sc.exe</code> and Net.
Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗
Persistence TA0003
T1136.001Create Account: Local Account×1
Adversaries may create a local account to maintain access to victim systems. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service.
Evidence: 2026-08-20/ransom-busters-rogue-affiliate-fake-recovery-firm · ATT&CK page ↗
Defense Impairment TA0112
T1685Disable or Modify Tools×1
Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.
Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗
Credential Access TA0006
T1003.001OS Credential Dumping: LSASS Memory×1
Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS). After a user logs on, the system generates and stores a variety of credential materials in LSASS process memory. These credential materials can be harvested by an administrative user or SYSTEM and used to conduct Lateral Movement using Use Alternate Authentication Material.
Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗
T1003.003OS Credential Dumping: NTDS×1
Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other information about domain members such as devices, users, and access rights. By default, the NTDS file (NTDS.dit) is located in <code>%SystemRoot%\NTDS\Ntds.dit</code> of a domain controller.
Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗
T1555Credentials from Password Stores×1
Adversaries may search for common password storage locations to obtain user credentials. Passwords are stored in several places on a system, depending on the operating system or application holding the credentials. There are also specific applications and services that store passwords to make them easier for users to manage and maintain, such as password managers and cloud secrets vaults. Once credentials are obtained, they can be used to perform lateral movement and access restricted information.
Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗
Discovery TA0007
T1046Network Service Discovery×2
Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation. Common methods to acquire this information include port, vulnerability, and/or wordlist scans using tools that are brought onto a system.
Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · 2026-08-20/ransom-busters-rogue-affiliate-fake-recovery-firm · ATT&CK page ↗
Lateral Movement TA0008
T1021.001Remote Services: Remote Desktop Protocol×1
Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user.
Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗
T1570Lateral Tool Transfer×1
Adversaries may transfer tools or other files between systems in a compromised environment. Once brought into the victim environment (i.e., Ingress Tool Transfer) files may then be copied from one system to another to stage adversary tools or other files over the course of an operation.
Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗
Command and Control TA0011
T1219Remote Access Tools×2
An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.
Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · 2026-08-20/ransom-busters-rogue-affiliate-fake-recovery-firm · ATT&CK page ↗
T1572Protocol Tunneling×1
Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of network packets that would otherwise not reach their intended destination, such as SMB, RDP, or other traffic that would be filtered by network appliances or not routed over the Internet.
Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗
Exfiltration TA0010
T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage×2
Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel. Cloud storage services allow for the storage, edit, and retrieval of data from a remote cloud storage server over the Internet.
Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · 2026-08-20/ransom-busters-rogue-affiliate-fake-recovery-firm · ATT&CK page ↗
Impact TA0040
T1657Financial Theft×1
Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.
Evidence: 2026-08-20/ransom-busters-rogue-affiliate-fake-recovery-firm · ATT&CK page ↗
Entries about Anubis (ransomware-as-a-service) (2)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- bleepingcomputer.com1 (33%)
- guidepointsecurity.com1 (33%)
- microsoft.com1 (33%)
All cited sources (3)
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/rogue-ransomware-affiliate-ransom-busters-poses-as-recovery-firm/
- guidepointsecurity.comGuidePoint Security (GRIT)https://www.guidepointsecurity.com/blog/beware-ransom-busters/
- microsoft.comMicrosoft Security Blog / Microsoft Threat Intelligencehttps://www.microsoft.com/en-us/security/blog/2026/09/24/beyond-ransomware-tracking-storm-2570-consistent-tradecraft-across-deployments/