Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Storm-2570 Ransomware Affiliate Reuses Post-Compromise Tools Across Multiple Campaigns

Storm-2570, a ransomware affiliate, has been observed employing a consistent set of post‑compromise tools across Qilin, DragonForce, Anubis, and BERT ransomware deployments. The repeatable tradecraft offers defenders actionable indicators to detect activity before encryption, underscoring the need for continuous monitoring and audit‑ready evidence.

LiveThreat™ Intelligence · 📅 September 25, 2026· 📰 microsoft.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
2 recommended
📰
Source
microsoft.com

Storm-2570 Ransomware Affiliate Reuses Post‑Compromise Tools Across Multiple Campaigns

What Happened – Storm‑2570, a ransomware affiliate, has been observed deploying a repeatable set of post‑compromise tools and techniques across deployments of Qilin, DragonForce, Anubis, and BERT ransomware. The group also publishes guidance to help defenders spot the activity before the ransomware payload encrypts data.

Why It Matters for Trust & Control Assurance

  • The consistent tradecraft creates a predictable detection surface that continuous‑control monitoring programs can target.
  • Mapping these known tools to your detection and response controls provides defensible evidence for audit readiness.
  • Demonstrating that you can identify and disrupt the post‑compromise phase aligns with the control objective of “detect and respond to malicious activity” and supports multiple frameworks (e.g., NIST CSF, ISO 27001).

Who Is Affected – Organizations of any size that run Windows‑based workloads, especially those in technology, cloud services, and financial sectors where ransomware remains a top threat.

Recommended Actions

  • Update endpoint detection and response (EDR) and network monitoring rules to include the specific tools and behaviors reported for Storm‑2570.
  • Validate that logging pipelines capture the relevant indicators of compromise and that evidence is retained for audit purposes.

Technical Notes – Storm‑2570’s post‑compromise toolkit includes custom PowerShell scripts, credential‑dumping utilities, and lateral‑movement binaries that are reused across Qilin, DragonForce, Anubis, and BERT ransomware families. No specific CVE is involved; the focus is on attacker methodology. Source: Microsoft Security Blog

📰 Original Source
https://www.microsoft.com/en-us/security/blog/2026/09/24/beyond-ransomware-tracking-storm-2570-consistent-tradecraft-across-deployments/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →