Storm-2570: analysis of the ransomware affiliate's techniques
Microsoft analyzes the consistent techniques used by the ransomware affiliate Storm-2570 prior to malware deployment.

Storm-2570 is a ransomware affiliate that uses consistent post-compromise tools and techniques across different deployments. These activities involve the Qilin, DragonForce, Anubis, and BERT ransomware.
Microsoft has tracked this behavior to provide useful guidance for defenders. The goal is to help detect and disrupt Storm-2570's malicious activities before the actual ransomware deployment occurs.
