
Storm-2570 Ransomware Operations Surge as Global Attacks Hit Record Highs
Microsoft Threat Intelligence reports a significant uptick in Storm-2570 activity, highlighting the evolving tradecraft of RaaS affiliates. This comes as global ransomware incidents reach record levels in late 2026.
Executive Takeaway — TL;DR
- Category:
- Threat Intelligence
- Severity:
- Critical
- Actor Type:
- Ransomware Group
- Geography:
- Global
- Confidence:
- High Confidence
- Source:
- Microsoft MSTIC
- Read Time:
- 4 min
Executive Summary
As of September 25, 2026, the global threat landscape is witnessing a record-breaking surge in ransomware activity. Recent intelligence from Microsoft indicates that the threat actor group Storm-2570 is refining its operational tradecraft, demonstrating a high degree of independence among its affiliates. This development coincides with broader industry data showing that August 2026 saw a record 997 ransomware attacks, marking a 23% increase in frequency and underscoring the persistent threat posed by Ransomware-as-a-Service (RaaS) models.
Threat Analysis
Storm-2570 has emerged as a focal point for security researchers due to its consistent and sophisticated deployment methods. Unlike traditional, monolithic ransomware gangs, Storm-2570 operates as a decentralized network of affiliates. This structure allows the group to scale operations rapidly while maintaining operational security. The group heavily utilizes double-extortion tactics, where sensitive data is exfiltrated prior to encryption, ensuring leverage even if the victim restores from backups.
Technical Details
Recent observations of Storm-2570 campaigns reveal a focus on initial access through credential harvesting and the exploitation of public-facing services. Once inside the network, the group employs living-off-the-land (LotL) techniques to minimize their footprint. They frequently utilize legitimate administrative tools to move laterally, escalate privileges, and disable security software before deploying their custom ransomware payload. The group has shown versatility, targeting both Windows and Linux environments, with a particular focus on virtualized infrastructure like ESXi servers to maximize the impact of their encryption.
Attribution Assessment
Attribution remains complex due to the RaaS model, which often obscures the distinction between the core developers and the affiliates executing the attacks. Microsoft Threat Intelligence identifies Storm-2570 as a highly capable, financially motivated actor. The group's behavior suggests a professionalized hierarchy, likely operating out of jurisdictions with limited international law enforcement cooperation, consistent with other major players like Qilin and the recently active KryBit group.
Implications
The record-breaking volume of attacks in 2026 indicates that current defensive measures are struggling to keep pace with the speed of RaaS innovation. The inter-group conflicts, such as the recent reported hack of Clop by ShinyHunters, demonstrate a volatile underground ecosystem where competition drives faster development of evasion techniques and more aggressive extortion demands.
Recommendations
Organizations must prioritize a defense-in-depth strategy. This includes implementing robust multi-factor authentication (MFA) across all external-facing services, conducting regular offline backups, and deploying endpoint detection and response (EDR) solutions configured to detect LotL activity. Security teams should specifically monitor for unauthorized use of administrative tools and anomalous data exfiltration patterns, which are hallmarks of the pre-encryption phase of Storm-2570 attacks.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Secp0 and Qilin Ransomware Groups Escalate Global Attacks on Real Estate and Electronics Sectors

LockBit 5.0 and Termite Ransomware Surge: New Attacks Hit Financial and Mortgage Sectors

