CTIPilot

Storm-2570

actor · actor:storm-2570 single-source

Microsoft-designated ransomware affiliate operating across the Qilin, DragonForce, Anubis and BERT RaaS ecosystems since April 2025, distinguished by a consistent commodity RMM/tunnelling/credential-theft/cloud-exfiltration toolkit reused regardless of the final payload brand; confirmed victims in healthcare, education, government agencies and services, financial services, energy, retail, IT and food/agriculture across the US, Canada, UK, Spain, the Netherlands and Puerto Rico (Microsoft, 2026-09-24).

Coverage timeline
1
first 2026-09-29 → last 2026-09-29
Peak priority
high
1 high
Sources cited
1
1 hosts
Sections touched
1
active-threats
Co-occurring entities
4
see Co-occurring entities below
ATT&CK techniques
11
pinned v19.2 · see below

ATT&CK techniques

11 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Execution TA0002

T1569.002System Services: Service Execution×1

Adversaries may abuse the Windows service control manager to execute malicious commands or payloads. The Windows service control manager (<code>services.exe</code>) is an interface to manage and manipulate services. The service control manager is accessible to users via GUI components as well as system utilities such as <code>sc.exe</code> and Net.

Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗

Defense Impairment TA0112

T1685Disable or Modify Tools×1

Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.

Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗

Credential Access TA0006

T1003.001OS Credential Dumping: LSASS Memory×1

Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS). After a user logs on, the system generates and stores a variety of credential materials in LSASS process memory. These credential materials can be harvested by an administrative user or SYSTEM and used to conduct Lateral Movement using Use Alternate Authentication Material.

Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗

T1003.003OS Credential Dumping: NTDS×1

Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other information about domain members such as devices, users, and access rights. By default, the NTDS file (NTDS.dit) is located in <code>%SystemRoot%\NTDS\Ntds.dit</code> of a domain controller.

Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗

T1555Credentials from Password Stores×1

Adversaries may search for common password storage locations to obtain user credentials. Passwords are stored in several places on a system, depending on the operating system or application holding the credentials. There are also specific applications and services that store passwords to make them easier for users to manage and maintain, such as password managers and cloud secrets vaults. Once credentials are obtained, they can be used to perform lateral movement and access restricted information.

Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗

Discovery TA0007

T1046Network Service Discovery×1

Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation. Common methods to acquire this information include port, vulnerability, and/or wordlist scans using tools that are brought onto a system.

Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗

Lateral Movement TA0008

T1021.001Remote Services: Remote Desktop Protocol×1

Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user.

Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗

T1570Lateral Tool Transfer×1

Adversaries may transfer tools or other files between systems in a compromised environment. Once brought into the victim environment (i.e., Ingress Tool Transfer) files may then be copied from one system to another to stage adversary tools or other files over the course of an operation.

Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗

Command and Control TA0011

T1219Remote Access Tools×1

An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.

Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗

T1572Protocol Tunneling×1

Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of network packets that would otherwise not reach their intended destination, such as SMB, RDP, or other traffic that would be filtered by network appliances or not routed over the Internet.

Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗

Exfiltration TA0010

T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage×1

Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel. Cloud storage services allow for the storage, edit, and retrieval of data from a remote cloud storage server over the Internet.

Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗

Story timeline

  1. 2026-09-29Storm-2570: a ransomware affiliate reuses a consistent commodity RMM/tunnelling/credential-theft toolkit across four separate RaaS brands, with government agencies among its confirmed victims
    active-threatsMicrosoft: the same toolkit rides into victims regardless of which ransomware brand signs the note

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

collaborates with

Where this entity is cited

  • active-threats1

Source distribution

  • microsoft.com1 (100%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Storm-2570 (1)

2026-09-29 · view entry permalink →

HIGHNATOB2

Storm-2570: a ransomware affiliate reuses a consistent commodity RMM/tunnelling/credential-theft toolkit across four separate RaaS brands, with government agencies among its confirmed victims

Microsoft Threat Intelligence profiles Storm-2570, a ransomware affiliate it has tracked since April 2025 that operates across multiple ransomware-as-a-service ecosystems rather than committing to one brand, deploying Qilin, DragonForce, Anubis and BERT payloads interchangeably against victims in healthcare, education, government agencies and services, financial services, energy, retail, IT and food/agriculture across the US, Canada, UK, Spain, the Netherlands and Puerto Rico (Microsoft Security Blog, 2026-09-24). Post-compromise, the affiliate routinely conducts internal network discovery using NetScan, SoftPerfect Network Scanner Portable and Nmap alongside native discovery commands and file-searching activity, to identify reachable hosts and services, map internal networks and locate systems, shares and files of interest ahead of credential access or encryption. Regardless of the final ransomware brand, Microsoft describes a recurring commodity toolchain across deployments: MeshAgent/MeshCentral, frequently renamed per-victim (for example meshagent64-[org].exe) and one of the affiliate's most frequently observed tools, as the operational bridge from initial access into account manipulation and credential access; Atera plus Splashtop, ScreenConnect, NinjaRMM, and, in one intrusion, a persistent LocalSystem-service Cloudflared.exe tunnel, and ngrok exposing RDP for redundant remote access; ntdsutil-driven Install-From-Media dumps of ntds.dit for offline domain-credential extraction; Mimikatz, LaZagne and pypykatz for credential harvesting; systematic Windows Defender tampering (disabling real-time monitoring, adding C:\PerfLogs exclusions, direct WinDefend registry edits) ahead of deployment; PsExec-driven lateral movement using @ip.txt host lists, including an rdp.bat script that force-enables RDP, alongside Impacket and NetExec over SMB; and s5cmd- or Rclone-based exfiltration to attacker-controlled S3 buckets ahead of double-extortion.

Because the toolkit, not the ransomware brand, is what recurs, defenders who alert only on a known ransomware binary or a specific RaaS brand's indicators will miss the affiliate entirely on its next engagement under a different payload. The consistent tradecraft gives a detection surface that survives a brand switch: a renamed MeshAgent binary establishing outbound C2, an ntdsutil IFM snapshot followed by offline credential extraction, a persistent-service Cloudflared.exe process, discovery-scanner activity (NetScan/Nmap) ahead of lateral movement, and s5cmd/Rclone processes initiating outbound transfers to cloud object storage are the behaviors Microsoft's reporting keys on across Storm-2570 engagements, independent of which ransomware note appears at the end. Microsoft's own post closes with a Defender XDR detection and mitigation mapping tied to each of these behaviors.

Triage: MeshAgent, Atera, ScreenConnect and NinjaRMM are legitimate tools many organizations already run for IT support; the discriminator is not the tool's presence but its provenance and configuration: a renamed executable (meshagent64-[org].exe rather than the vendor's own binary name), an RMM agent installed outside a change-managed deployment window, or a Cloudflared.exe process registered as a persistent LocalSystem service rather than invoked interactively are the signals Microsoft's own telemetry keys on.

Microsoft Threat Intelligence has observed Storm-2570 in multiple investigated intrusions affecting organizations in United States, Canada, United Kingdom, Spain, Netherlands, and Puerto Rico, including healthcare and public health, education, government agencies and services, financial services, energy, consumer retail, Information technology (IT), food and agriculture, consumer services, commercial facilities, non-government organization (NGO), chemicals, critical manufacturing, and transportation.

Microsoft Security Blog / Microsoft Threat Intelligence 2026-09-24

Builds on: 2026-09-21/qilin-ai-generated-wiper-locker-scripts-forensic-markers

threat29 Sep 04:55Zsingle-sourceOpen finding ↗