Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Local AI Model Modifies Credential Dumper to Bypass EDR Detection
September 26, 2026
F-Droid 2.0 Released: Major Redesign Improves Open-Source Android App Discovery
September 26, 2026
OpenAI Agents Autonomously Attempt Website Exploits
September 26, 2026
Home/CyberSecurity News/Microsoft Details BlackMatter & Conti Ransomware’s Shared Attack Blueprint
CyberSecurity News

Microsoft Details BlackMatter & Conti Ransomware’s Shared Attack Blueprint

Key Takeaways Microsoft has identified a single ransomware affiliate, Storm-2570, responsible for attacks deploying at least four distinct ransomware families: Qilin, DragonForce, Anubis, and BERT....

Jennifer sherman
Jennifer sherman
September 25, 2026 5 Min Read
15 0

Key Takeaways

  • Microsoft has identified a single ransomware affiliate, Storm-2570, responsible for attacks deploying at least four distinct ransomware families: Qilin, DragonForce, Anubis, and BERT.
  • The group employs a consistent “attack blueprint” involving remote management tool deployment, credential theft, security control evasion, and data exfiltration to cloud storage, regardless of the final ransomware payload.
  • Storm-2570’s operations, tracked since April 2025, have impacted organizations across various critical sectors including healthcare, education, energy, and manufacturing in North America and Europe.
  • This consistent methodology allows for earlier detection of intrusions, enabling defenders to identify the threat actor before the ransomware encryption phase.

Ransomware Affiliate Storm-2570 Leverages Consistent Attack Blueprint Across Multiple Malware Families

Cybersecurity researchers at Microsoft have uncovered a sophisticated ransomware affiliate, identified as Storm-2570, utilizing a uniform attack methodology across various ransomware campaigns. This group has been linked to incidents culminating in the deployment of at least four different ransomware strains: Qilin, DragonForce, Anubis, and BERT. The findings highlight a strategic shift by threat actors to leverage consistent operational tactics, thereby obscuring their identity behind diverse ransomware brands.

Table Of Content

  • Key Takeaways
  • Ransomware Affiliate Storm-2570 Leverages Consistent Attack Blueprint Across Multiple Malware Families
  • Initial Access and Persistence
  • Lateral Movement and Privilege Escalation
  • Data Exfiltration and Ransomware Deployment
  • What You Should Do

Since its emergence in April 2025, Storm-2570 has executed attacks against organizations in the United States, Canada, the United Kingdom, Spain, the Netherlands, and Puerto Rico. These attacks have spanned a broad spectrum of industries, including critical sectors like healthcare, education, energy, and manufacturing, as detailed in a Microsoft report.

The significance of this discovery lies in its potential to empower defenders. By recognizing the recurring patterns of compromise, security teams can detect and respond to an ongoing intrusion much earlier in the attack chain, rather than waiting for the tell-tale signs of data encryption.

Initial Access and Persistence

While Microsoft has not yet pinpointed the initial vector Storm-2570 uses to breach victim networks, their analysis reveals a highly consistent post-initial access playbook. Once inside, the attackers prioritize establishing persistent remote access. They achieve this by installing various remote management software. Frequently observed tools include MeshAgent, sometimes paired with MeshCentral, as well as Atera, NinjaRMM, ScreenConnect, Splashtop, and Remotely_Agent.

A common tactic employed by the operators involves renaming the MeshAgent executable to mimic legitimate files associated with the victim organization, a deceptive measure designed to evade detection.

To further maintain covert access, Storm-2570 deploys tunneling tools. In one documented instance, a Cloudflare Tunnel was configured to run automatically with elevated privileges, creating an encrypted outbound connection to attacker infrastructure. Other cases have shown the use of ngrok to expose remote desktop access. These actions allow the attackers to blend their malicious activity with legitimate remote administration, making detection more challenging.

Lateral Movement and Privilege Escalation

Following initial persistence, the threat actors systematically enumerate and scout for valuable systems, accounts, and sensitive data within the compromised network. They leverage network scanners and employ credential harvesting tools such as Mimikatz, LaZagne, and pypykatz to escalate privileges. Microsoft also observed the group utilizing the built-in Windows utility ntdsutil.exe to copy Active Directory data (NTDS.dit), a technique that can expose critical password hashes across the victim’s domain.

Before deploying their final ransomware payload, Storm-2570 actively works to weaken security defenses and spread across the network. This includes disabling real-time protection, configuring antivirus exclusions, and making registry modifications. Lateral movement is then executed using tools like PsExec, Impacket, NetExec, or through remote desktop scripts. The observed misuse of MeshAgent in other recent ransomware investigations underscores why any unexpected remote management agent installation should be thoroughly investigated.

Data Exfiltration and Ransomware Deployment

A critical phase preceding ransomware deployment involves data exfiltration. Storm-2570 frequently moves sensitive files to attacker-controlled cloud storage. They use utilities such as s5cmd to copy documents, spreadsheets, databases, and archives into S3 buckets. Rclone is also employed for ongoing file synchronization. This dual extortion strategy ensures that even if victims manage to restore encrypted systems, their sensitive information remains compromised, adding significant pressure for ransom payment.

Microsoft’s report did not provide specific figures on the total number of victims or an estimate of financial losses, nor did it detail how many intrusions progressed from data exfiltration to full ransomware deployment. However, the consistent use of scanning, remote access, and cloud uploads aligns with patterns observed in other ransomware affiliate operations. This suggests that the identity of the final ransomware deployed is less important than recognizing the underlying attack methodologies.

Security responders are urged to analyze the entire intrusion chain rather than solely focusing on the ransomware note. Early indicators like unexpected remote tools, credential dumping, changes to antivirus settings, and rapid cloud data transfers, when viewed collectively, provide a clearer warning of an impending ransomware attack. The continuity of an operator’s habits across different ransomware families means that these early signals remain valuable for defense.

What You Should Do

  • Limit Account Privileges: Implement the principle of least privilege for all user and service accounts to restrict potential damage from compromised credentials.
  • Strengthen Credential Practices: Enforce strong, unique passwords and consider passwordless authentication where feasible. Regularly audit and rotate credentials for high-privilege accounts.
  • Protect Security Settings: Configure and protect endpoint security settings (e.g., antivirus, EDR) against unauthorized tampering, including disabling real-time protection or adding exclusions.
  • Require Multifactor Authentication (MFA): Mandate MFA for all remote access services and approved remote management tools to prevent unauthorized access even if credentials are stolen.
  • Monitor and Investigate Remote Tools: Actively monitor for the installation and use of remote management software (e.g., MeshAgent, Atera, ScreenConnect). Investigate any unapproved installations immediately and reset credentials for accounts used in their deployment.
  • Detect Unusual Cloud Transfers: Implement monitoring for unusual or large-scale data transfers to cloud storage services, especially those involving tools like s5cmd or Rclone.
  • Audit Remote Desktop Access: Monitor for attempts to enable or open Remote Desktop Protocol (RDP) access, and review RDP connection history for suspicious activity.
  • Review Indicators of Compromise (IoCs): Integrate the provided IoCs into your security monitoring tools to detect known malicious files and activities associated with Storm-2570.

Indicators of Compromise (IoCs):

Type Indicator Description
File name pattern meshagent64-[organization name].exe Example of a MeshAgent executable renamed to include the victim organization’s name. The bracketed text is a placeholder, not a literal filename.
File name Cloudflared.exe Tunneling utility used to maintain outbound remote access. <a rel="noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/0010be19-0999-4c41-9847-1f3ac0bc9ea1/Microsoft-Finds-Ransomware-Group-Using-Same-Attack-Blueprint-Across-Multiple-Malware-Families.pdf?AWSAccessKeyId=ASIA2F3EMEYE2VGXIMKV&Signature=91ldVB7TK31E34r07zGUUc8SCdI%3D&x-amz-security-token=IQoJb3JpZ2luX2VjECEaCXVzLWVhc3QtMSJIMEYCIQDXJ7NAHbwA%2Bp%2BqzEBBx32Iegb4d%2FSHZNz1xDs2eq5yLQIhAKR%2BKKf0wwb%2Bph97N0%2FACW3EKop57DK56QpqZc2N%2F3QhKoMFCOn%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1Igxhoyp6Z9EGS3VJHWcq1wTVMxGL7kNPDHq8KSJIlzoJZbXmg4oZrkRV375gRY0BWbo8g1%2B1ft4%2BPk0v15zrihTuRETAfDMBXwVZrrbf2olVNziEwkgmE2KfZnT1yiZ2g2iInyDXzsWBiBvbuU8VP8pJ4sCVrqRCiCeyL%2Bnc8GPAZUR6l%2FVuF4tnbBXC3eLurf9E7r2VeHgTcgYUSFrMCS2PzsnawjkcZWFD8DE2%2F9QHCq4ECsDEahj9b%2FAiTMsZ2kzZ26yk6cjgSkFfuo820bW%2BOZVDe%2FqHjYifg1MKmynweUBvwxrRn%2Fir4vfvypVkkOSsyV1E2Q%2FUxeCDy6aAxGeDK7S64fpXUZRmKfDCmJpPhXtyhbMTFr0SvvKA0we8CCJDuH8zI9dkb9NSbXW9T2bu7GSU0FQl0N%2Fpts%2BIzJgn1WSKzX9CHk1LLP9VB4NJYdcaEWMOJx9t1ccBy0oTQpT9lLdxPNoqt45tgqr1mr9CpYc1ReRaPh5rVmkeey1yOw2yUZAV8cbGL8R%2FhBhMqP8qS61uAEErdmVVIp83UfBy%2FeF8NyV9llG8pIQS80wBjKNi4WJzqcrhFiv0Jr59N83G13m4fYicX%2Bg743NOZMPOiYZ%2B%2FqxfK8pAnzO%2FmYTsxQeKpPNTELiTrC8P

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwareransomwareSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

AI Agents Attempted to Hack Public Websites After Data Access Failure

Next Post

Google Ads Campaign Spreads Fake Security Alerts, Pushes Malware

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Linux Kernel Flaw (CVE-2024-0001) Lets Local Users Gain Root, Escape Containers
September 25, 2026
AI-Powered Botnet “DarkGate” Found Operating Inside Compromised Servers
September 25, 2026
Critical Samsung Flaw Lets Attackers Install Cryptominers
September 25, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us