News Room
16
Share
Microsoft Links Storm 2570 Affiliate to Multi-Ransomware Campaign
highThreat Intelligence

Microsoft Links Storm 2570 Affiliate to Multi-Ransomware Campaign

Microsoft has identified a prolific ransomware affiliate, Storm 2570, orchestrating attacks using Qilin, DragonForce, Anubis, and BERT ransomware. The group utilizes consistent credential theft and remote access tools.

28 September 2026Last updated 28 September 20264 min readMicrosoft MSTIC
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Threat Intelligence
Severity:
High
Actor Type:
Ransomware Group
Geography:
Global
Confidence:
High Confidence
Source:
Microsoft MSTIC
Read Time:
4 min

Executive Summary

Recent intelligence from Microsoft has identified a highly active ransomware affiliate, tracked as Storm 2570, which is currently leveraging multiple ransomware-as-a-service (RaaS) platforms to conduct widespread extortion campaigns. Unlike traditional operators tied to a single codebase, Storm 2570 acts as a versatile affiliate, deploying various payloads including Qilin, DragonForce, Anubis, and BERT ransomware. This shift highlights the increasing modularity of the modern cybercriminal ecosystem.

Threat Analysis

Storm 2570 has demonstrated a sophisticated operational tempo, focusing on organizations across multiple international jurisdictions. By operating as an affiliate, the group maintains a consistent set of tactics, techniques, and procedures (TTPs) regardless of the specific ransomware strain deployed. This consistency allows the group to maintain high efficiency in initial access and lateral movement, effectively treating the ransomware payload as a commodity service.

Technical Details

The group’s methodology relies heavily on the exploitation of remote management tools and aggressive credential harvesting. Once initial access is gained—often through compromised credentials or exploited edge devices—Storm 2570 deploys custom scripts to disable security software and exfiltrate sensitive data before triggering encryption. The use of diverse ransomware strains suggests that the group may be testing different RaaS programs to optimize their extortion success rates or to bypass specific security controls that might be tuned to detect known signatures of a single family.

Attribution Assessment

Microsoft’s tracking of Storm 2570 as an affiliate rather than a primary developer provides a clearer picture of the threat landscape. By focusing on the actor's infrastructure and behavioral patterns, defenders can better correlate seemingly disparate incidents. The group’s ability to pivot between Qilin and other emerging ransomware families indicates a high level of technical proficiency and a deep integration into the underground RaaS economy.

Implications

This development underscores the danger of the 'affiliate-first' model in ransomware operations. Organizations can no longer rely on signature-based detection for specific ransomware families to protect their environments. The threat is no longer just the malware, but the persistent, adaptable actor behind the keyboard who can switch payloads at will to maximize impact and evade detection.

Recommendations

  1. Implement robust multi-factor authentication (MFA) across all remote access points to mitigate credential theft.
  2. Monitor for unauthorized use of remote management and administrative tools, which are frequently abused by Storm 2570.
  3. Adopt a behavioral-based detection strategy that focuses on the TTPs of the affiliate rather than the specific ransomware binary.
  4. Ensure that incident response plans account for the possibility of double-extortion, where data exfiltration occurs prior to encryption.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo