Cybersecuritynews iconCybersecuritynewsSep 25, 2026

Microsoft Finds Ransomware Group Using Same Attack Blueprint Across Multiple Malware Families

Microsoft has linked a ransomware affiliate to attacks that ended with four different ransomware families. The group, tracked as Storm-2570, repeatedly used the same methods to take control of networks, steal data and prepare systems for encryption.

Microsoft Finds Ransomware Group Using Same Attack Blueprint Across Multiple Malware Families

Share this story

Send the public story page.

Useful takeaways from this story.

Microsoft has linked a ransomware affiliate to attacks that ended with four different ransomware families.

The group, tracked as Storm-2570, repeatedly used the same methods to take control of networks, steal data and prepare systems for encryption.

The changing ransomware name often concealed a familiar operator.

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

Microsoft has linked a ransomware affiliate to attacks that ended with four different ransomware families. The group, tracked as Storm-2570, repeatedly used the same methods to take control of networks, steal data and prepare systems for encryption. The changing ransomware name often concealed a familiar operator.

Details worth keeping

The changing ransomware name often concealed a familiar operator. Storm-2570 has been tracked since April 2025.

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app