HIGHransomware·

Storm-2570 Ransomware Affiliate Tradecraft Analysis

Storm-2570 is a ransomware affiliate known for deploying Qilin, DragonForce, Anubis, and BERT ransomware. This report highlights their consistent post-compromise tradecraft, emphasizing the importance of early detection to disrupt operations before ransomware deployment.

This report was researched and drafted by an AI agent and reviewed by a human analyst prior to publication. View the agent workflow →

Overview

Storm-2570 is a ransomware affiliate group that consistently employs similar post-compromise tools and techniques across various ransomware deployments. This group has been observed deploying Qilin, DragonForce, Anubis, and BERT ransomware families. Understanding their consistent tradecraft is crucial for defenders to detect and disrupt their activities before the final ransomware payload is executed.

Technical Analysis

Storm-2570 operates as a ransomware affiliate, indicating they likely gain initial access and establish persistence before deploying one of several ransomware families. Their operations are characterized by consistent post-compromise tradecraft, suggesting a standardized playbook for internal network reconnaissance, privilege escalation, lateral movement, and data exfiltration, culminating in ransomware deployment.
* Ransomware Families Observed: Qilin, DragonForce, Anubis, BERT.
* Attack Vector: Not specified in the provided source, but typically involves initial access methods like phishing, exploiting public-facing applications, or compromised credentials.
* Prerequisites: Successful initial compromise and establishment of a foothold within the target environment.

Detection

Detection efforts should focus on the consistent post-compromise activities that precede ransomware deployment. While specific tools are not detailed in the provided source, common ransomware affiliate behaviors include:
* Suspicious process creation by services or system accounts (e.g., cmd.exe, powershell.exe).
* Execution of legitimate administrative tools for malicious purposes (e.g., PsExec, net.exe, wmic.exe).
* Deletion of shadow copies using vssadmin.exe.
* Attempts to disable security software.
* Abnormal network connections for data exfiltration or command and control.

Sigma Detection Rules

⚠️ AI-generated detection rules. These are experimental starting points. Review field names, EventIDs, and logic against your environment’s schema before deploying. Tune to reduce false positives.

Ransomware – Shadow Copy Deletion via Vssadmin

title: Ransomware - Shadow Copy Deletion via Vssadmin
id: 9a0b1c2d-3e4f-5a6b-7c8d-9e0f1a2b3c4d
status: experimental
description: Detects attempts to delete shadow copies using vssadmin.exe, a common precursor to ransomware encryption.
logsource:
  product: windows
  service: sysmon
detection:
  selection:
    EventID: 1
    Image|endswith: '\\vssadmin.exe'
    CommandLine|contains: 'delete shadows'
  condition: selection
level: high

Suspicious Process Creation by Services

title: Suspicious Process Creation by Services
id: 1a2b3c4d-5e6f-7a8b-9c0d-1e2f3a4b5c6d
status: experimental
description: Detects common command-line interpreters or administrative tools spawned by services, which can indicate post-compromise activity by ransomware affiliates.
logsource:
  product: windows
  service: sysmon
detection:
  selection:
    EventID: 1
    ParentImage|endswith:
      - '\\services.exe'
      - '\\svchost.exe'
    Image|endswith:
      - '\\cmd.exe'
      - '\\powershell.exe'
      - '\\pwsh.exe'
      - '\\wmic.exe'
      - '\\mshta.exe'
      - '\\regsvr32.exe'
  condition: selection
level: medium

Mitigations

  1. Implement strong access controls and least privilege: Limit user and service account permissions to only what is necessary.
  2. Patch and update systems regularly: Prioritize patching internet-facing applications and systems.
  3. Deploy endpoint detection and response (EDR) solutions: Monitor for suspicious process activity, file modifications, and network connections.
  4. Regularly back up critical data: Ensure backups are isolated and immutable to prevent ransomware encryption.
  5. Educate users on phishing and social engineering: Reduce the risk of initial access via user compromise.

References

Indicators of Compromise

No public IOCs available at time of writing.

MITRE ATT&CK

  • T1059 — Command and Scripting Interpreter
  • T1082 — System Information Discovery
  • T1018 — Remote System Discovery
  • T1021 — Remote Services
  • T1490 — Inhibit System Recovery
  • T1486 — Data Encrypted for Impact
🤖 AI Attribution
Generated by gemini-2.5-flash ·
1,609 input / 1,235 output tokens ·
Reviewed and approved by a human analyst before publication
#ransomware#high#ransomware#storm-2570#threat-group#windows