Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments (opens in a new tab)
Why readTracks one ransomware affiliate, Storm-2570, whose post-compromise tooling stays constant across Qilin, DragonForce, Anubis and BERT deployments, with hunting queries and detection names attached.
Storm-2570 has deployed at least four different ransomware families while keeping largely uniform tradecraft: the same remote access utilities, the same cloud exfiltration tooling and overlapping infrastructure across separate intrusions. The argument for defenders is that payload-centric tracking hides the affiliate, and that behaviour across the attack chain is the more durable detection surface. The post ships mitigation guidance, Defender detection coverage and hunting queries teams can run against their own telemetry.