Threats · 14h ago
Microsoft Threat Intelligence says Storm-2570 has used the same post-compromise tradecraft across intrusions tied to Qilin, DragonForce, Anubis, and BERT ransomware. The crew has been tracked since April 2025 and has been seen in cases across the United States, Canada, the United Kingdom, Spain, the Netherlands, and Puerto Rico.
The pattern is not the payload but the behavior: recurring remote access, credential theft, lateral movement, security tampering, and cloud exfiltration, along with infrastructure overlap and the same tooling. That means a hunt built only around a ransomware family name or hash can miss the same affiliate when it rebrands, even before encryption starts.
For defenders, the durable exposure sits at the actor layer. If your visibility stops at the final malware label, the same intrusion team can keep surfacing under different brands while leaving a recognizable trail in the attack chain.
1 source covering this story
Storm-2570 is a ransomware affiliate that uses consistent post-compromise tools and techniques across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware, and provides guidance to help defenders detect and disrupt this activity before ransomware deployment.
Part of the PlainSec briefing for 2026-09-25