BlackTree Security · Infrastructure · Automation · AI

Microsoft Traces Four Ransomware Brands to One Repeating Playbook

Microsoft tracks Storm-2570 across incidents ending in Qilin, DragonForce, Anubis and BERT ransomware. The affiliate changes payloads while repeatedly using similar tools before encryption. That makes its earlier behaviour a useful target for defenders.

The repeatable activity matters before the ransom note

Microsoft reports legitimate remote-management software, credential-dumping utilities, lateral execution, Defender tampering and cloud exfiltration across its investigations. Examples include ScreenConnect, Mimikatz, PsExec and Rclone. The company has not confirmed a single initial-access method for the cluster, and its tracking label does not establish that every incident involved one individual.

The report includes hunting guidance for this recurring activity. It describes observed intrusions rather than a complete count of victims or a forecast that every user of these tools faces the same attack.

Build a sequence, not a software blacklist

A new remote agent may be an approved support deployment. A file-transfer tool may be part of a backup job. Investigators need the installation owner, tenant, initiating identity and business purpose before treating either as malicious.

The stronger signal is an unexplained sequence: remote access appears, sensitive credentials are accessed, execution moves between machines, protections change and data leaves. Join that timeline across endpoint, identity and network records. A detection tied only to the final encryptor can miss the earlier period when containment has the most value.

  • Inventory approved RMM software. Record expected products, tenants, installer identities, owners and deployment paths. Treat anything else as an investigation trigger.
  • Protect remote-management accounts. Require multifactor authentication, restrict administrative access and monitor new agent enrolment and tenant changes.
  • Use tamper protection. Centralise Defender policy and prevent local administrators from silently adding exclusions where operationally possible.
  • Correlate dual-use tools. Join RMM installation, PsExec or WMI activity, credential access, tunnels and object-storage transfers into one incident view.
  • Hunt before the payload name is known. Microsoft’s report includes detection mappings and hunting queries for repeated parts of the chain.
  • Prepare containment for remote agents. Security teams should be able to revoke an unapproved RMM tenant, block its infrastructure and isolate affected hosts without waiting for encryption.

BlackTree previously covered remote-management abuse in another ransomware campaign and how quickly a modern intrusion can reach impact. Storm-2570 adds a strategic lesson: tooling and behaviour can be more stable than the criminal brand printed on the ransom note.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *