#ParsedReport #CompletenessMedium
26-09-2026
Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments
https://www.microsoft.com/en-us/security/blog/2026/09/24/beyond-ransomware-tracking-storm-2570-consistent-tradecraft-across-deployments/
Report completeness: Medium
Actors/Campaigns:
Storm-2570 (motivation: information_theft, financially_motivated)
Threats:
Bert_ransomware
Qilin_ransomware
Dragonforce
Anubis
Atera_tool
Meshagent_tool
Screenconnect_tool
Splashtop_tool
Ninjaone_tool
Netscan_tool
Nmap_tool
Impacket_tool
Netexec_tool
S5cmd_tool
Rclone_tool
Meshcentral_tool
Credential_dumping_technique
Ntdsutil_tool
Ngrok_tool
Mimikatz_tool
Lazagne_tool
Pypykatz_tool
Psexec_tool
Psexecremote_tool
Dragonforce_ransomware
Ransom:win32/qilinloader
Victims:
Healthcare and public health, Education, Government agencies and services, Financial services, Energy, Consumer retail, Information technology, Food and agriculture, Consumer services, Commercial facilities, have more...
Industry:
Transport, Government, Ngo, Energy, Chemical, Healthcare, Education, Foodtech, Retail
Geo:
Puerto rico, United kingdom, Netherlands, Spain, Canada, United states
TTPs:
Tactics: 7
Technics: 0
IOCs:
File: 6
Soft:
Microsoft Defender, Microsoft Defender for Endpoint, PsExec, Cloudflare, SoftPerfect Network Scanner, Active Directory
Win Services:
WinDefend
Languages:
python, powershell
Post #32750
15