Microsoft Tracked Storm-2570 Ransomware Actor
The group has utilized four distinct ransomware brands across critical infrastructure sectors since April 2025.
Updated on Sept. 29, 2026 in Cybersecurity

Live Poll
Do you trust that current digital security measures adequately protect your personal and work accounts?
Microsoft has identified a persistent threat actor known as Storm-2570, which has deployed four different ransomware strains against organizations in the United States, Canada, the United Kingdom, Spain, the Netherlands, and Puerto Rico. The analysis published on September 24, 2026, details a group that maintains consistent techniques despite switching between ransomware brands.
Why it matters
Storm-2570 targets critical infrastructure sectors including healthcare, government, and financial services, posing a broad threat to essential global services. The group's ability to rotate ransomware brands while maintaining identical operational tradecraft demonstrates the evolving nature of affiliate-led cyberattacks.
Storm-2570 has deployed Qilin, DragonForce, Anubis, and BERT ransomware across its campaigns. The group utilizes a suite of remote management tools including Atera, MeshAgent, and ScreenConnect to sustain its operations.
The players
Microsoft
A global technology company providing cloud computing, operating systems, and comprehensive enterprise security threat intelligence.
Storm-2570
A persistent threat actor group known for deploying diverse ransomware brands and maintaining consistent operational techniques across multiple sectors.
The details
The actor frequently renames legitimate MeshAgent binaries with victim-themed filenames to avoid detection. For lateral movement and credential access, the group leverages established utilities such as Mimikatz, a tool that extracts plaintext passwords and hashes from Windows memory, and PsExec, a program for executing processes on remote systems. Furthermore, attackers stage registry hive data from Active Directory domain controllers to harvest credential hashes before exfiltrating data via tools like Rclone to S3-compatible storage.
Timeline
Microsoft began tracking Storm-2570 intrusions in April 2025.
Microsoft published its detailed analysis on September 24, 2026.
The Tech Race
This finding follows a broader trend where threat actors shift between ransomware-as-a-service providers to obfuscate their origins and evade security controls. It places Storm-2570 in the same operational category as other agile, multi-brand syndicates monitored by global intelligence researchers.
Organizations in the healthcare, government, and financial services sectors are the primary targets for these campaigns and should audit their use of remote management software. Defenders should specifically look for signs of unauthorized use of Atera, MeshAgent, and ScreenConnect, which are frequently repurposed by this group.
The takeaway
Storm-2570 illustrates that the brand of ransomware deployed is often a secondary concern compared to the underlying actor's consistent methodology. Security teams should monitor for the specific tools and lateral movement patterns described in the Microsoft report, regardless of which specific malware strain appears in an alert.
Further reading
For more on evolving threat landscapes, visit Cybersecurity.
Source note: This article includes information reported by ESecurityPlanet.
Live Poll
Do you trust that current digital security measures adequately protect your personal and work accounts?







