
Microsoft Links Storm 2570 Affiliate to Multi-Ransomware Campaign
Microsoft has identified a prolific ransomware affiliate, Storm 2570, orchestrating attacks using Qilin, DragonForce, Anubis, and BERT ransomware. The group utilizes consistent credential theft and remote access tools.
Executive Takeaway — TL;DR
- Category:
- Threat Intelligence
- Severity:
- High
- Actor Type:
- Ransomware Group
- Geography:
- Global
- Confidence:
- High Confidence
- Source:
- Microsoft MSTIC
- Read Time:
- 4 min
Executive Summary
Recent intelligence from Microsoft has identified a highly active ransomware affiliate, tracked as Storm 2570, which is currently leveraging multiple ransomware-as-a-service (RaaS) platforms to conduct widespread extortion campaigns. Unlike traditional operators tied to a single codebase, Storm 2570 acts as a versatile affiliate, deploying various payloads including Qilin, DragonForce, Anubis, and BERT ransomware. This shift highlights the increasing modularity of the modern cybercriminal ecosystem.
Threat Analysis
Storm 2570 has demonstrated a sophisticated operational tempo, focusing on organizations across multiple international jurisdictions. By operating as an affiliate, the group maintains a consistent set of tactics, techniques, and procedures (TTPs) regardless of the specific ransomware strain deployed. This consistency allows the group to maintain high efficiency in initial access and lateral movement, effectively treating the ransomware payload as a commodity service.
Technical Details
The group’s methodology relies heavily on the exploitation of remote management tools and aggressive credential harvesting. Once initial access is gained—often through compromised credentials or exploited edge devices—Storm 2570 deploys custom scripts to disable security software and exfiltrate sensitive data before triggering encryption. The use of diverse ransomware strains suggests that the group may be testing different RaaS programs to optimize their extortion success rates or to bypass specific security controls that might be tuned to detect known signatures of a single family.
Attribution Assessment
Microsoft’s tracking of Storm 2570 as an affiliate rather than a primary developer provides a clearer picture of the threat landscape. By focusing on the actor's infrastructure and behavioral patterns, defenders can better correlate seemingly disparate incidents. The group’s ability to pivot between Qilin and other emerging ransomware families indicates a high level of technical proficiency and a deep integration into the underground RaaS economy.
Implications
This development underscores the danger of the 'affiliate-first' model in ransomware operations. Organizations can no longer rely on signature-based detection for specific ransomware families to protect their environments. The threat is no longer just the malware, but the persistent, adaptable actor behind the keyboard who can switch payloads at will to maximize impact and evade detection.
Recommendations
- Implement robust multi-factor authentication (MFA) across all remote access points to mitigate credential theft.
- Monitor for unauthorized use of remote management and administrative tools, which are frequently abused by Storm 2570.
- Adopt a behavioral-based detection strategy that focuses on the TTPs of the affiliate rather than the specific ransomware binary.
- Ensure that incident response plans account for the possibility of double-extortion, where data exfiltration occurs prior to encryption.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Ransomware Surge: Over 1,000 Organizations Compromised in August 2026 Amidst Escalating Gang Conflicts

Global Ransomware Surge: September 2026 Intelligence Update on ShinyHunters and MedusaLocker Activity

