Microsoft Identifies Storm-2570 Ransomware Group Behind Multiple Campaigns Across Six Nations
AI-generated from multiple sources. Verify before acting on this reporting.
WASHINGTON (Sept. 24, 2026) — Microsoft Threat Intelligence has identified a persistent ransomware affiliate known as Storm-2570 as the operator behind a coordinated series of cyberattacks utilizing four distinct malware families across six countries. The group's consistent tradecraft and shared infrastructure link it to deployments of Qilin, DragonForce, Anubis, and BERT ransomware variants.
The campaign has targeted organizations in the United States, Canada, the United Kingdom, Spain, the Netherlands, and Puerto Rico. Microsoft analysts noted that while the malware families differ in their initial encryption mechanisms, the underlying infrastructure used to command and control the attacks remains identical across all incidents. This overlap indicates a single operational entity managing multiple ransomware-as-a-service campaigns rather than independent actors.
Storm-2570 has demonstrated a high degree of operational flexibility by rotating between different ransomware strains. The group's use of Qilin, DragonForce, Anubis, and BERT suggests an ability to adapt quickly to defensive measures or specific target vulnerabilities. By maintaining consistent network infrastructure while varying the payload, the affiliate complicates attribution efforts for victim organizations and law enforcement agencies attempting to trace the attacks back to a single source.
The geographic scope of the activity spans North America and Western Europe, with significant presence in the United States and the United Kingdom. Attacks in Spain, the Netherlands, Canada, and Puerto Rico further illustrate the group's international reach. The timing of these coordinated deployments suggests a strategic effort to maximize disruption across multiple sectors simultaneously.
Microsoft stated that the identification of Storm-2570 marks a significant development in understanding the evolution of ransomware ecosystems. The ability to switch between different malware families while maintaining core infrastructure allows affiliates to evade signature-based detection systems designed for specific threats. This modularity has become a defining characteristic of modern ransomware operations.
The motivation behind Storm-2570's multi-strain approach remains unclear. Analysts have not yet determined whether the group is testing market conditions, responding to specific client demands, or attempting to bypass security controls that target individual malware signatures. The lack of public claims from the group regarding these specific campaigns has left questions unanswered regarding their ultimate objectives.
As investigations continue, cybersecurity firms are working with affected organizations in the six nations to contain the spread of the malware and restore encrypted systems. The identification of the shared infrastructure provides a critical avenue for disrupting the group's operations, though the group's ability to pivot between different ransomware families suggests it may remain active despite ongoing countermeasures.
The full extent of the damage caused by Storm-2570 across the targeted regions is still being assessed. Authorities have not yet confirmed whether any specific critical infrastructure sectors were compromised or if financial data was exfiltrated alongside the encryption activities.