Executive Summary
Storm-2570, a cross-ecosystem ransomware affiliate tracked by Microsoft since April 2025, has demonstrated consistent attack patterns across multiple ransomware-as-a-service (RaaS) operations including Qilin, DragonForce, Anubis, and BERT. The threat actor has targeted organizations across 14 sectors in the United States, Canada, United Kingdom, Spain, Netherlands, and Puerto Rico, maintaining uniform tradecraft involving remote management tools like MeshAgent, credential harvesting utilities, and cloud exfiltration tools such as s5cmd and Rclone regardless of the final ransomware payload deployed.
This case highlights the growing trend of ransomware affiliates operating independently across multiple RaaS ecosystems, shifting between operations to maximize payout opportunities. The consistent use of commodity tools and techniques across different ransomware families demonstrates how threat actors are becoming more adaptable and sophisticated in their approach to enterprise compromise.
Why This Matters Now
The emergence of cross-ecosystem ransomware affiliates like Storm-2570 represents a significant evolution in the ransomware landscape, requiring defenders to focus on behavioral patterns rather than specific payloads to effectively detect and prevent attacks.
Attack Path Analysis
Storm-2570 established initial access through undisclosed means, then deployed multiple RMM tools (MeshAgent, Atera, ScreenConnect) for persistence and remote control. The threat actor escalated privileges using credential dumping tools like ntdsutil and Mimikatz to obtain domain administrator access. Lateral movement occurred through PsExec, Impacket, and NetExec with RDP enablement scripts across multiple hosts. Command and control was maintained via tunneling tools like Cloudflared and ngrok alongside persistent RMM agents. Data exfiltration was performed using s5cmd and Rclone to transfer sensitive files to attacker-controlled S3 buckets. Final impact involved deploying multiple ransomware variants (Qilin, DragonForce, Anubis, BERT) after disabling security controls.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Storm-2570 gained initial access to target networks through undetermined means, likely involving credential compromise or exploitation of internet-facing services
MITRE ATT&CK® Techniques
Remote Access Software
NTDS
Lateral Tool Transfer
Disable or Modify Tools
Exfiltration Over C2 Channel
Data Encrypted for Impact
Remote Desktop Protocol
Windows Command Shell
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Deploy a change- and tamper-detection mechanism
Control ID: 11.5.1
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.15
DORA – ICT risk management framework
Control ID: Article 11
CISA ZTMM 2.0 – Identity and Access Management
Control ID: Identity
NIS2 Directive – Cybersecurity risk-management measures
Control ID: Article 21(2)(a)
ISO 27001 – Management of technical vulnerabilities
Control ID: A.12.6.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Health Care / Life Sciences
Storm-2570's ransomware-as-a-service attacks exploit healthcare's critical infrastructure dependencies, targeting patient data through lateral movement and encrypted traffic vulnerabilities requiring HIPAA compliance.
Financial Services
Multi-cloud environments and east-west traffic in financial services face Storm-2570's credential harvesting and zero-trust segmentation bypass techniques, compromising PCI DSS compliance frameworks.
Government Administration
Government agencies encounter Storm-2570's consistent tradecraft across multiple ransomware families, exploiting inadequate egress security and multicloud visibility gaps in critical infrastructure systems.
Higher Education/Acadamia
Educational institutions suffer from Storm-2570's remote management tool abuse and data exfiltration capabilities, targeting research data through compromised Kubernetes security and cloud firewall weaknesses.
Sources
- Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deploymentshttps://www.microsoft.com/en-us/security/blog/2026/09/24/beyond-ransomware-tracking-storm-2570-consistent-tradecraft-across-deployments/Verified
- CISA Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/known-exploited-vulnerabilities-catalogVerified
- MITRE ATT&CK Framework - Ransomware Techniqueshttps://attack.mitre.org/techniques/T1486/Verified
- Microsoft Defender Attack Surface Reduction Ruleshttps://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/attack-surface-reductionVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have significantly constrained Storm-2570's multi-stage attack by limiting lateral movement paths and reducing the overall blast radius across compromised cloud environments.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial compromise scope would likely be contained to specific workload segments, preventing immediate access to broader cloud infrastructure and reducing the attacker's initial foothold visibility.
Control: Zero Trust Segmentation
Mitigation: Credential dumping activities would likely face restricted access to domain controllers and authentication systems, constraining the attacker's ability to escalate privileges across segmented network zones.
Control: East-West Traffic Security
Mitigation: Lateral movement tools would likely encounter restricted east-west traffic flows, significantly limiting the attacker's ability to spread across multiple hosts and reducing the number of systems they could compromise.
Control: Multicloud Visibility & Control
Mitigation: Command and control communications would likely face detection and potential blocking across cloud environments, constraining the attacker's ability to maintain persistent remote access and coordinate activities across multiple platforms.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration attempts would likely encounter egress policy restrictions, constraining the volume and types of data that could be transferred to external S3 buckets and reducing successful data theft.
Ransomware deployment would likely be confined to fewer systems due to previous segmentation controls, reducing the overall scope of encryption and limiting the business impact across cloud workloads.
Impact at a Glance
Affected Business Functions
- IT Infrastructure Management
- Data Security Operations
- Business Continuity Services
- Customer Data Processing
Estimated downtime: 18 days
Estimated loss: $2,500,000
Multi-sector data exposure affecting healthcare records, financial services customer data, educational institution records, government agency information, and critical infrastructure operational data. Storm-2570 uses advanced exfiltration tools (s5cmd, Rclone) for systematic data theft across multiple industries including healthcare, finance, education, and government sectors.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with identity-based policies to prevent lateral movement via PsExec and RDP across network boundaries
- • Deploy Egress Security & Policy Enforcement to block unauthorized S3 exfiltration using s5cmd and Rclone to external cloud storage
- • Enable Multicloud Visibility & Control with anomaly detection to identify suspicious RMM tool deployments and tunneling activities
- • Enforce East-West Traffic Security monitoring to detect and block internal reconnaissance using NetScan, Nmap, and credential dumping attempts
- • Activate Threat Detection & Anomaly Response capabilities to baseline normal behavior and alert on covert tools like MeshAgent and Cloudflared tunnels



