In brief: Microsoft attributes deployments of Qilin, DragonForce, Anubis and BERT to the same affiliate, Storm-2570. The final ransomware changes, but remote access, credential theft, lateral movement and exfiltration tooling remains largely consistent. Those pre-encryption behaviours are more useful to defenders than the payload's brand.
Confirmed: four payloads, a recurring toolchain
Microsoft has tracked Storm-2570 since April 2025 and observed it in investigated incidents across the United States, Canada, United Kingdom, Spain, Netherlands and Puerto Rico. Sectors included healthcare, education, government, finance, energy, IT, manufacturing and transport. This is Microsoft telemetry from multiple investigations, not a global victim count.
After an unconfirmed initial-access step, the affiliate repeatedly uses legitimate remote-management software: MeshAgent and MeshCentral, Atera, ScreenConnect, Splashtop, Remotely_Agent and NinjaRMM. Binaries or services are sometimes renamed after the victim organisation. Cloudflare Tunnel and ngrok provide encrypted outbound access that can bypass inbound firewall restrictions.
Microsoft lists NetScan, Nmap, PsExec, Impacket, NetExec and RDP scripts for discovery and lateral movement. Mimikatz, LaZagne, pypykatz and ntdsutil support credential access, including copies of NTDS.dit. Defender tampering follows, then Rclone or s5cmd moves data to S3-compatible storage before one of the four ransomware families is deployed.
Pandorex Analysis: detect the operator before encryption
The added value is not a novel technique but a stable combination across changing ransomware brands. Teams searching only for Qilin or DragonForce indicators may identify the common operator late. Unexpected RMM installations, renamed MeshAgent services, ntdsutil backups on domain controllers, new Defender exclusions and s5cmd beside a credential file form a stronger payload-independent hunt chain.
Microsoft recommends tamper protection, MFA for approved RMM systems, tighter lateral-movement controls and attack-surface-reduction rules covering credential theft and PsExec/WMI process creation. CISA separately maintains cross-sector ransomware hardening and response guidance. A local allowlist of approved remote tools is essential because these programs are dual-use; their presence alone does not establish an intrusion.
Microsoft has not confirmed the initial-access method or disclosed a total number of compromised organisations. Claims about Storm-2570's prevalence or growth are therefore not sufficiently supported.
