Microsoft Tracks Storm-2570 Tradecraft Across Ransomware Deployments
Microsoft published an analysis of Storm-2570’s consistent post-compromise tools and techniques. The post offers guidance to help defenders detect and disrupt the activity before ransomware deployment.

MicrosoftMicrosoft published a post on its Security Blog titled "Beyond the ransomware: Tracking Storm-2570's consistent tradecraft across deployments." The post examines Storm-2570, describing it as a ransomware affiliate.
According to the post, Storm-2570 uses consistent post-compromise tools and techniques across deployments involving the Qilin, DragonForce, Anubis, and BERT ransomware. This points to a recurring operational pattern across different deployments.
The post provides guidance intended to help defenders detect and disrupt this activity before ransomware deployment. That guidance focuses on the post-compromise stage preceding the final ransomware execution.
Readers should consult the original post on the Microsoft Security Blog for the full details and defensive guidance. They should also verify the publication date on the official source, September 24, 2026, to check whether the material has since been updated.
Original publication date
September 24, 2026
