Microsoft Finds Ransomware Group Using Same Attack Blueprint Across Multiple Malware Families

Microsoft Finds Ransomware Group Using Same Attack Blueprint Across Multiple Malware Families

By Tushar Subhra Dutta
Publication Date: 2026-09-25 10:11:00

Microsoft has linked a ransomware affiliate to attacks that ended with four different ransomware families. The group, tracked as Storm-2570, repeatedly used the same methods to take control of networks, steal data and prepare systems for encryption.

The changing ransomware name often concealed a familiar operator. Storm-2570 has been tracked since April 2025. Its intrusions have affected organizations in the United States, Canada, the United Kingdom, Spain, the Netherlands and Puerto Rico, across sectors ranging from healthcare and education to energy and manufacturing.

Microsoft has not established how the group first enters victim networks. Analysts from Microsoft identified a consistent pattern after access was gained, even when attacks ended with Qilin, DragonForce, Anubis or BERT ransomware.

The overlap matters because investigators can spot the same attacker before the final malware arrives, rather than waiting for an encryption alert.

Microsoft said in a…