Storm-2570 Ransomware Affiliate Tradecraft Analysis
Storm-2570 is a ransomware affiliate known for deploying Qilin, DragonForce, Anubis, and BERT ransomware. This report highlights their consistent post-compromise tradecraft, emphasizing the importance of early detection to disrupt operations before ransomware deployment.
Overview
Storm-2570 is a ransomware affiliate group that consistently employs similar post-compromise tools and techniques across various ransomware deployments. This group has been observed deploying Qilin, DragonForce, Anubis, and BERT ransomware families. Understanding their consistent tradecraft is crucial for defenders to detect and disrupt their activities before the final ransomware payload is executed.
Technical Analysis
Storm-2570 operates as a ransomware affiliate, indicating they likely gain initial access and establish persistence before deploying one of several ransomware families. Their operations are characterized by consistent post-compromise tradecraft, suggesting a standardized playbook for internal network reconnaissance, privilege escalation, lateral movement, and data exfiltration, culminating in ransomware deployment.
* Ransomware Families Observed: Qilin, DragonForce, Anubis, BERT.
* Attack Vector: Not specified in the provided source, but typically involves initial access methods like phishing, exploiting public-facing applications, or compromised credentials.
* Prerequisites: Successful initial compromise and establishment of a foothold within the target environment.
Detection
Detection efforts should focus on the consistent post-compromise activities that precede ransomware deployment. While specific tools are not detailed in the provided source, common ransomware affiliate behaviors include:
* Suspicious process creation by services or system accounts (e.g., cmd.exe, powershell.exe).
* Execution of legitimate administrative tools for malicious purposes (e.g., PsExec, net.exe, wmic.exe).
* Deletion of shadow copies using vssadmin.exe.
* Attempts to disable security software.
* Abnormal network connections for data exfiltration or command and control.
Sigma Detection Rules
Ransomware – Shadow Copy Deletion via Vssadmin
title: Ransomware - Shadow Copy Deletion via Vssadmin
id: 9a0b1c2d-3e4f-5a6b-7c8d-9e0f1a2b3c4d
status: experimental
description: Detects attempts to delete shadow copies using vssadmin.exe, a common precursor to ransomware encryption.
logsource:
product: windows
service: sysmon
detection:
selection:
EventID: 1
Image|endswith: '\\vssadmin.exe'
CommandLine|contains: 'delete shadows'
condition: selection
level: high
Suspicious Process Creation by Services
title: Suspicious Process Creation by Services
id: 1a2b3c4d-5e6f-7a8b-9c0d-1e2f3a4b5c6d
status: experimental
description: Detects common command-line interpreters or administrative tools spawned by services, which can indicate post-compromise activity by ransomware affiliates.
logsource:
product: windows
service: sysmon
detection:
selection:
EventID: 1
ParentImage|endswith:
- '\\services.exe'
- '\\svchost.exe'
Image|endswith:
- '\\cmd.exe'
- '\\powershell.exe'
- '\\pwsh.exe'
- '\\wmic.exe'
- '\\mshta.exe'
- '\\regsvr32.exe'
condition: selection
level: medium
Mitigations
- Implement strong access controls and least privilege: Limit user and service account permissions to only what is necessary.
- Patch and update systems regularly: Prioritize patching internet-facing applications and systems.
- Deploy endpoint detection and response (EDR) solutions: Monitor for suspicious process activity, file modifications, and network connections.
- Regularly back up critical data: Ensure backups are isolated and immutable to prevent ransomware encryption.
- Educate users on phishing and social engineering: Reduce the risk of initial access via user compromise.
References
Indicators of Compromise
No public IOCs available at time of writing.
MITRE ATT&CK
T1059— Command and Scripting InterpreterT1082— System Information DiscoveryT1018— Remote System DiscoveryT1021— Remote ServicesT1490— Inhibit System RecoveryT1486— Data Encrypted for Impact
Generated by
gemini-2.5-flash ·1,609 input / 1,235 output tokens ·
Reviewed and approved by a human analyst before publication