{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/actors/storm-2570/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":["Storm-2570"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["high"],"_cs_tags":["ransomware","rmm-abuse","tunneling","post-compromise"],"_cs_type":"threat","_cs_vendors":[],"content_html":"\u003cp\u003eStorm-2570 is a ransomware affiliate active since April 2025 that operates across multiple Ransomware-as-a-Service (RaaS) ecosystems, including Qilin, DragonForce, Anubis, and BERT. Microsoft Threat Intelligence analysis reveals that Storm-2570 maintains highly consistent post-compromise tradecraft regardless of the ransomware payload ultimately deployed. The actor relies heavily on the abuse of legitimate Remote Monitoring and Management (RMM) tools and tunneling utilities to maintain persistent access, perform reconnaissance, and facilitate data exfiltration.\u003c/p\u003e\n\u003cp\u003eBy focusing on uniform behaviors - such as the unauthorized deployment of RMM agents, the creation of persistent tunnels, and the use of specific discovery and credential dumping utilities - defenders can detect and disrupt this actor's activity in the early stages of the intrusion. This cross-ecosystem consistency demonstrates that tracking ransomware threats by payload alone is insufficient for identifying and mitigating persistent affiliates. Storm-2570 has targeted organizations across various sectors, including healthcare, government, finance, and critical manufacturing, in multiple countries including the United States, United Kingdom, and Canada.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInitial access is established through unidentified vectors, followed by hands-on-keyboard activity to gain a foothold.\u003c/li\u003e\n\u003cli\u003eDeployment of RMM tools, such as MeshAgent, AteraAgent, or Remotely_Agent, often renamed to mimic legitimate organizational services.\u003c/li\u003e\n\u003cli\u003eExecution of discovery tools, including NetScan, Nmap, and network batch scripts, to map the environment and identify domain assets.\u003c/li\u003e\n\u003cli\u003eCredential access activities, including the use of ntdsutil for dumping Active Directory databases.\u003c/li\u003e\n\u003cli\u003eLateral movement via PsExec, Impacket, or RDP, utilizing administrative credentials harvested during the discovery phase.\u003c/li\u003e\n\u003cli\u003eEstablishment of persistent outbound communication channels using tunneling utilities such as Cloudflared or ngrok to maintain access and bypass inbound firewall controls.\u003c/li\u003e\n\u003cli\u003eData collection and exfiltration using utilities like s5cmd or Rclone to move sensitive data to attacker-controlled cloud storage.\u003c/li\u003e\n\u003cli\u003eDeployment of ransomware (e.g., Qilin, DragonForce, Anubis, or BERT) to execute the final objective of encryption and extortion.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful compromise by Storm-2570 results in the theft of sensitive organizational data, deployment of ransomware, and significant operational disruption. The actor has successfully targeted critical sectors including healthcare, government services, and critical manufacturing, demonstrating the potential for broad socioeconomic impact. By rotating between multiple ransomware ecosystems, Storm-2570 ensures flexibility in their monetization strategy, making them a consistent and dangerous threat to enterprise networks.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eEnable process-creation logging (e.g., Sysmon Event ID 1) to monitor for the execution of RMM tools and discovery utilities listed in this brief.\u003c/li\u003e\n\u003cli\u003eImplement a policy to allowlist or restrict the installation of unauthorized remote access software, specifically targeting known RMM tools like MeshAgent, Atera, and ScreenConnect.\u003c/li\u003e\n\u003cli\u003eMonitor for anomalous outbound network connections associated with tunneling utilities like Cloudflared.exe and ngrok; restrict these tools to only known, authorized business processes.\u003c/li\u003e\n\u003cli\u003eAudit administrative credential usage and restrict the use of tools like ntdsutil and PsExec to authorized system management accounts.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rules below to detect unauthorized renaming of RMM binaries and suspicious tunnel creation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-24T20:11:13Z","date_published":"2026-09-24T20:11:13Z","id":"https://feed.craftedsignal.io/briefs/2026-09-storm-2570-tradecraft/","summary":"Storm-2570 is a persistent ransomware affiliate that uses standardized post-compromise tooling across multiple RaaS ecosystems to conduct lateral movement and exfiltration.","title":"Tracking Storm-2570 Ransomware Affiliate Tradecraft","url":"https://feed.craftedsignal.io/briefs/2026-09-storm-2570-tradecraft/"}],"language":"en","title":"CraftedSignal Threat Feed - Storm-2570","version":"https://jsonfeed.org/version/1.1"}