Microsoft Details BlackMatter & Conti Ransomware’s Shared Attack Blueprint
Key Takeaways Microsoft has identified a single ransomware affiliate, Storm-2570, responsible for attacks deploying at least four distinct ransomware families: Qilin, DragonForce, Anubis, and BERT....
Key Takeaways
- Microsoft has identified a single ransomware affiliate, Storm-2570, responsible for attacks deploying at least four distinct ransomware families: Qilin, DragonForce, Anubis, and BERT.
- The group employs a consistent “attack blueprint” involving remote management tool deployment, credential theft, security control evasion, and data exfiltration to cloud storage, regardless of the final ransomware payload.
- Storm-2570’s operations, tracked since April 2025, have impacted organizations across various critical sectors including healthcare, education, energy, and manufacturing in North America and Europe.
- This consistent methodology allows for earlier detection of intrusions, enabling defenders to identify the threat actor before the ransomware encryption phase.
Ransomware Affiliate Storm-2570 Leverages Consistent Attack Blueprint Across Multiple Malware Families
Cybersecurity researchers at Microsoft have uncovered a sophisticated ransomware affiliate, identified as Storm-2570, utilizing a uniform attack methodology across various ransomware campaigns. This group has been linked to incidents culminating in the deployment of at least four different ransomware strains: Qilin, DragonForce, Anubis, and BERT. The findings highlight a strategic shift by threat actors to leverage consistent operational tactics, thereby obscuring their identity behind diverse ransomware brands.
Table Of Content
Since its emergence in April 2025, Storm-2570 has executed attacks against organizations in the United States, Canada, the United Kingdom, Spain, the Netherlands, and Puerto Rico. These attacks have spanned a broad spectrum of industries, including critical sectors like healthcare, education, energy, and manufacturing, as detailed in a Microsoft report.
The significance of this discovery lies in its potential to empower defenders. By recognizing the recurring patterns of compromise, security teams can detect and respond to an ongoing intrusion much earlier in the attack chain, rather than waiting for the tell-tale signs of data encryption.
Initial Access and Persistence
While Microsoft has not yet pinpointed the initial vector Storm-2570 uses to breach victim networks, their analysis reveals a highly consistent post-initial access playbook. Once inside, the attackers prioritize establishing persistent remote access. They achieve this by installing various remote management software. Frequently observed tools include MeshAgent, sometimes paired with MeshCentral, as well as Atera, NinjaRMM, ScreenConnect, Splashtop, and Remotely_Agent.
A common tactic employed by the operators involves renaming the MeshAgent executable to mimic legitimate files associated with the victim organization, a deceptive measure designed to evade detection.
To further maintain covert access, Storm-2570 deploys tunneling tools. In one documented instance, a Cloudflare Tunnel was configured to run automatically with elevated privileges, creating an encrypted outbound connection to attacker infrastructure. Other cases have shown the use of ngrok to expose remote desktop access. These actions allow the attackers to blend their malicious activity with legitimate remote administration, making detection more challenging.
Lateral Movement and Privilege Escalation
Following initial persistence, the threat actors systematically enumerate and scout for valuable systems, accounts, and sensitive data within the compromised network. They leverage network scanners and employ credential harvesting tools such as Mimikatz, LaZagne, and pypykatz to escalate privileges. Microsoft also observed the group utilizing the built-in Windows utility ntdsutil.exe to copy Active Directory data (NTDS.dit), a technique that can expose critical password hashes across the victim’s domain.
Before deploying their final ransomware payload, Storm-2570 actively works to weaken security defenses and spread across the network. This includes disabling real-time protection, configuring antivirus exclusions, and making registry modifications. Lateral movement is then executed using tools like PsExec, Impacket, NetExec, or through remote desktop scripts. The observed misuse of MeshAgent in other recent ransomware investigations underscores why any unexpected remote management agent installation should be thoroughly investigated.
Data Exfiltration and Ransomware Deployment
A critical phase preceding ransomware deployment involves data exfiltration. Storm-2570 frequently moves sensitive files to attacker-controlled cloud storage. They use utilities such as s5cmd to copy documents, spreadsheets, databases, and archives into S3 buckets. Rclone is also employed for ongoing file synchronization. This dual extortion strategy ensures that even if victims manage to restore encrypted systems, their sensitive information remains compromised, adding significant pressure for ransom payment.
Microsoft’s report did not provide specific figures on the total number of victims or an estimate of financial losses, nor did it detail how many intrusions progressed from data exfiltration to full ransomware deployment. However, the consistent use of scanning, remote access, and cloud uploads aligns with patterns observed in other ransomware affiliate operations. This suggests that the identity of the final ransomware deployed is less important than recognizing the underlying attack methodologies.
Security responders are urged to analyze the entire intrusion chain rather than solely focusing on the ransomware note. Early indicators like unexpected remote tools, credential dumping, changes to antivirus settings, and rapid cloud data transfers, when viewed collectively, provide a clearer warning of an impending ransomware attack. The continuity of an operator’s habits across different ransomware families means that these early signals remain valuable for defense.
What You Should Do
- Limit Account Privileges: Implement the principle of least privilege for all user and service accounts to restrict potential damage from compromised credentials.
- Strengthen Credential Practices: Enforce strong, unique passwords and consider passwordless authentication where feasible. Regularly audit and rotate credentials for high-privilege accounts.
- Protect Security Settings: Configure and protect endpoint security settings (e.g., antivirus, EDR) against unauthorized tampering, including disabling real-time protection or adding exclusions.
- Require Multifactor Authentication (MFA): Mandate MFA for all remote access services and approved remote management tools to prevent unauthorized access even if credentials are stolen.
- Monitor and Investigate Remote Tools: Actively monitor for the installation and use of remote management software (e.g., MeshAgent, Atera, ScreenConnect). Investigate any unapproved installations immediately and reset credentials for accounts used in their deployment.
- Detect Unusual Cloud Transfers: Implement monitoring for unusual or large-scale data transfers to cloud storage services, especially those involving tools like s5cmd or Rclone.
- Audit Remote Desktop Access: Monitor for attempts to enable or open Remote Desktop Protocol (RDP) access, and review RDP connection history for suspicious activity.
- Review Indicators of Compromise (IoCs): Integrate the provided IoCs into your security monitoring tools to detect known malicious files and activities associated with Storm-2570.
Indicators of Compromise (IoCs):



No Comment! Be the first one.