Tracking Storm-2570 Ransomware Affiliate Tradecraft
Storm-2570 is a persistent ransomware affiliate that uses standardized post-compromise tooling across multiple RaaS ecosystems to conduct lateral movement and exfiltration.
Storm-2570 is a ransomware affiliate active since April 2025 that operates across multiple Ransomware-as-a-Service (RaaS) ecosystems, including Qilin, DragonForce, Anubis, and BERT. Microsoft Threat Intelligence analysis reveals that Storm-2570 maintains highly consistent post-compromise tradecraft regardless of the ransomware payload ultimately deployed. The actor relies heavily on the abuse of legitimate Remote Monitoring and Management (RMM) tools and tunneling utilities to maintain persistent access, perform reconnaissance, and facilitate data exfiltration.
By focusing on uniform behaviors - such as the unauthorized deployment of RMM agents, the creation of persistent tunnels, and the use of specific discovery and credential dumping utilities - defenders can detect and disrupt this actor's activity in the early stages of the intrusion. This cross-ecosystem consistency demonstrates that tracking ransomware threats by payload alone is insufficient for identifying and mitigating persistent affiliates. Storm-2570 has targeted organizations across various sectors, including healthcare, government, finance, and critical manufacturing, in multiple countries including the United States, United Kingdom, and Canada.
Attack Chain
- Initial access is established through unidentified vectors, followed by hands-on-keyboard activity to gain a foothold.
- Deployment of RMM tools, such as MeshAgent, AteraAgent, or Remotely_Agent, often renamed to mimic legitimate organizational services.
- Execution of discovery tools, including NetScan, Nmap, and network batch scripts, to map the environment and identify domain assets.
- Credential access activities, including the use of ntdsutil for dumping Active Directory databases.
- Lateral movement via PsExec, Impacket, or RDP, utilizing administrative credentials harvested during the discovery phase.
- Establishment of persistent outbound communication channels using tunneling utilities such as Cloudflared or ngrok to maintain access and bypass inbound firewall controls.
- Data collection and exfiltration using utilities like s5cmd or Rclone to move sensitive data to attacker-controlled cloud storage.
- Deployment of ransomware (e.g., Qilin, DragonForce, Anubis, or BERT) to execute the final objective of encryption and extortion.
Impact
Successful compromise by Storm-2570 results in the theft of sensitive organizational data, deployment of ransomware, and significant operational disruption. The actor has successfully targeted critical sectors including healthcare, government services, and critical manufacturing, demonstrating the potential for broad socioeconomic impact. By rotating between multiple ransomware ecosystems, Storm-2570 ensures flexibility in their monetization strategy, making them a consistent and dangerous threat to enterprise networks.
Recommendation
- Enable process-creation logging (e.g., Sysmon Event ID 1) to monitor for the execution of RMM tools and discovery utilities listed in this brief.
- Implement a policy to allowlist or restrict the installation of unauthorized remote access software, specifically targeting known RMM tools like MeshAgent, Atera, and ScreenConnect.
- Monitor for anomalous outbound network connections associated with tunneling utilities like Cloudflared.exe and ngrok; restrict these tools to only known, authorized business processes.
- Audit administrative credential usage and restrict the use of tools like ntdsutil and PsExec to authorized system management accounts.
- Deploy the Sigma rules below to detect unauthorized renaming of RMM binaries and suspicious tunnel creation.
Immediate actions
Deploy Sigma rules for RMM and tunnel discovery
Threat Hunt
Search for unauthorized RMM agent execution
Data: Process creation logs showing Atera, MeshAgent, or ScreenConnect
Mitigations
Restrict outbound communication for tunneling utilities
T1572
Detection coverage 2
Detect Suspicious Renaming of MeshAgent
highDetects MeshAgent RMM binaries renamed with organization-specific tags to masquerade as legitimate services.
Detect Cloudflared Tunnel Service Installation
highDetects the creation of a Cloudflared service for persistent outbound tunneling.
Detection queries are available on the platform. Get full rules →