{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Data exfiltration and ransomware encryption represent the ultimate objective of the Storm-2570 threat actor; a negative result over these stages confirms the attack chain was broken early."
      },
      "name": "Storm-2570 Data Exfiltration and Ransomware Impact",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1041",
        "attack.t1567.002",
        "attack.t1486",
        "attack.t1003.001",
        "attack.t1021.001"
      ],
      "series": {
        "slug": "beyond-the-ransomware-tracking-storm-2570-s-consistent-tradecraft-across-deployments",
        "index": 3,
        "title": "Beyond the ransomware: Tracking Storm-2570\u2019s consistent tradecraft across deployments",
        "total": 3
      },
      "related": [
        {
          "hunt": "storm-2570-rmm-persistence",
          "reason": "This hunt focuses on final impact; initial persistence and RMM usage are handled in a preceding hunt.",
          "relation": "out-of-scope-alternative"
        },
        {
          "hunt": "storm-2570-rmm-tunneling-persistence",
          "relation": "follows"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "network": {
          "name": "Network telemetry",
          "category": "network",
          "telemetry": [
            "network"
          ]
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A standard rule might alert on rclone, but this hunt correlates process execution, attributed aggregate network volume via 5-tuple joins, and file system burst activity to provide the high-confidence context required for a critical isolation decision.",
      "coverage": [
        {
          "stage": "exfiltration-cloud-storage",
          "steps": [
            "exfil-tool-execution",
            "high-volume-outbound"
          ],
          "status": "covered"
        },
        {
          "stage": "ransomware-impact",
          "steps": [
            "file-impact-indicators"
          ],
          "status": "covered"
        },
        {
          "stage": "rmm-persistence-and-execution",
          "reason": "Handled in a separate hunt focused on MeshAgent and other RMM tools.",
          "status": "out_of_scope"
        },
        {
          "stage": "c2-protocol-tunneling",
          "reason": "Handled in a separate hunt focused on cloudflared and ngrok.",
          "status": "out_of_scope"
        },
        {
          "stage": "network-and-file-discovery",
          "reason": "Handled in a separate hunt focused on NetScan and nmap.",
          "status": "out_of_scope"
        },
        {
          "stage": "credential-dumping-ad",
          "reason": "Handled in a separate hunt focused on ntdsutil and mimikatz.",
          "status": "out_of_scope"
        },
        {
          "stage": "defense-evasion-tampering",
          "reason": "Handled in a separate hunt focused on Defender tampering.",
          "status": "out_of_scope"
        },
        {
          "stage": "lateral-movement-psexec-rdp",
          "reason": "Handled in a separate hunt focused on PsExec and batch-enabled RDP.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Persistence via RMM Tooling",
            "slug": "rmm-persistence-and-execution",
            "tactic": "persistence",
            "techniques": [
              "T1021.006"
            ],
            "observables": [
              "meshagent64.exe",
              "AteraAgent.exe",
              "Splashtop Streamer",
              "NinjaRMM",
              "Remotely_Agent",
              "MeshAgent-related binaries renamed to victim-themed names like meshagent64-[organization].exe",
              "Base64-encoded command execution via RMM"
            ]
          },
          {
            "name": "Persistent Outbound Tunneling",
            "slug": "c2-protocol-tunneling",
            "tactic": "command-and-control",
            "techniques": [
              "T1572"
            ],
            "observables": [
              "Cloudflared.exe installed as a service under LocalSystem",
              "ngrok exposing TCP 3389",
              "Persistent Cloudflare Tunnel service creation"
            ]
          },
          {
            "name": "Internal Discovery",
            "slug": "network-and-file-discovery",
            "tactic": "discovery",
            "techniques": [
              "T1018",
              "T1046"
            ],
            "observables": [
              "NetScan.exe",
              "SoftPerfect Network Scanner Portable",
              "nmap.exe",
              "Native Windows discovery commands for host identification"
            ]
          },
          {
            "name": "Active Directory Database Dumping",
            "slug": "credential-dumping-ad",
            "tactic": "credential-access",
            "techniques": [
              "T1003",
              "T1003.001"
            ],
            "observables": [
              "ntdsutil.exe",
              "ntdsutil 'ac i ntds' 'ifm' 'create full C:\\Windows\\Temp\\'",
              "ntds.dit extraction",
              "Mimikatz",
              "LaZagne",
              "pypykatz"
            ]
          },
          {
            "name": "Security Software Tampering",
            "slug": "defense-evasion-tampering",
            "tactic": "defense-evasion",
            "techniques": [
              "T1562.001"
            ],
            "observables": [
              "Microsoft Defender exclusions for C:\\PerfLogs",
              "Registry value DisableAntiSpyware set to 1",
              "Registry value DisableRealtimeMonitoring set to 1",
              "Modification of WinDefend service keys"
            ]
          },
          {
            "name": "Lateral Movement and Remote Execution",
            "slug": "lateral-movement-psexec-rdp",
            "tactic": "lateral-movement",
            "techniques": [
              "T1021.001",
              "T1021.002"
            ],
            "observables": [
              "PsExec.exe using host lists like @ip.txt",
              "rdp.bat enabling RDP access",
              "NetExec SMB commands",
              "Impacket offensive framework",
              "reg add Terminal Server /v fDenyTSConnections /d 0",
              "netsh advfirewall firewall add rule name=\"Remote Desktop\" localport=3389"
            ]
          },
          {
            "name": "Data Staging and Exfiltration",
            "slug": "exfiltration-cloud-storage",
            "tactic": "exfiltration",
            "techniques": [
              "T1041",
              "T1567.002"
            ],
            "observables": [
              "s5cmd.exe",
              "rclone.exe",
              "Outbound data transfers to cloud storage providers"
            ]
          },
          {
            "name": "Data Encryption for Impact",
            "slug": "ransomware-impact",
            "tactic": "impact",
            "techniques": [
              "T1486"
            ],
            "observables": [
              "Qilin ransomware",
              "DragonForce ransomware",
              "Anubis ransomware",
              "BERT ransomware"
            ]
          }
        ],
        "summary": "Storm-2570 is a ransomware affiliate that employs a consistent set of RMM tools, tunneling utilities, and hands-on-keyboard techniques to deploy payloads like Qilin and DragonForce. They prioritize persistent remote access via MeshAgent and Cloudflared tunnels before moving to Active Directory credential dumping and broad lateral movement using PsExec and RDP."
      },
      "severity": "critical",
      "rationale": "Focus on file servers and domain controllers where Storm-2570 frequently stages NTDS.dit files and conducts mass encryption.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An intruder is exfiltrating staged directories and Active Directory database fragments using synchronization tools before deploying a ransomware payload for mass encryption.",
      "parameters": {
        "exfil_tools": {
          "from": {
            "ref": "msrc-blog",
            "kind": "article",
            "observed": "2026-09-24"
          },
          "type": "list[string]",
          "default": [
            "rclone.exe",
            "s5cmd.exe"
          ],
          "description": "Names of exfiltration and synchronization tools."
        },
        "scope_hosts": {
          "from": {
            "ref": "analyst-scoping",
            "kind": "manual",
            "observed": "2026-09-24"
          },
          "type": "list[host]",
          "default": [],
          "description": "Limit the hunt to these hostnames; leave empty to hunt across the estate."
        },
        "lookback_days": {
          "from": {
            "ref": "default-retention",
            "kind": "manual",
            "observed": "2026-09-24"
          },
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "scope_processes": {
          "from": {
            "ref": "analyst-scoping",
            "kind": "manual",
            "observed": "2026-09-24"
          },
          "type": "list[string]",
          "default": [],
          "description": "Limit impact searches to these process names; leave empty for all processes."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.microsoft.com/en-us/security/blog/2026/09/24/beyond-ransomware-tracking-storm-2570-consistent-tradecraft-across-deployments/",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.microsoft.com/en-us/security/blog/2026/09/24/beyond-ransomware-tracking-storm-2570-consistent-tradecraft-across-deployments/",
          "name": "Beyond the ransomware: Tracking Storm-2570\u2019s consistent tradecraft across deployments"
        }
      ],
      "blind_spots": [
        {
          "id": "no-network-flow-logs",
          "risk": "A negative result does not prove exfiltration did not occur; it only proves it was not seen on the flow surface.",
          "stage": "exfiltration-cloud-storage",
          "question": "the total volume of data exfiltrated by a specific process",
          "requires": "hb_network_connection flow log provider (state_kind = log)"
        },
        {
          "id": "low-level-api-encryption",
          "risk": "Advanced ransomware may use drivers or low-level disk access to encrypt data without generating standard file activity rows.",
          "stage": "ransomware-impact",
          "question": "whether encryption is occurring via APIs that bypass standard activity logging",
          "requires": "kernel-level file monitor on every host"
        }
      ]
    },
    "name": "Storm-2570 Data Exfiltration and Ransomware Impact",
    "description": "This hunt targets the final, high-impact stages of a Storm-2570 intrusion. It first identifies the execution of exfiltration tools, the staging of the NTDS database, and the use of RDP enablement scripts. It then attributes large network outbound transfers to specific processes by joining endpoint socket states with network flow logs. Finally, it corroborates these signals with rapid file modification bursts to identify active ransomware events."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "beyond-the-ransomware-tracking-storm-2570-s-consistent-tradecraft-across-deployments",
          "index": 3,
          "title": "Beyond the ransomware: Tracking Storm-2570\u2019s consistent tradecraft across deployments",
          "total": 3
        },
        "coverage": [
          {
            "stage": "exfiltration-cloud-storage",
            "steps": [
              "exfil-tool-execution",
              "high-volume-outbound"
            ],
            "status": "covered"
          },
          {
            "stage": "ransomware-impact",
            "steps": [
              "file-impact-indicators"
            ],
            "status": "covered"
          },
          {
            "stage": "rmm-persistence-and-execution",
            "reason": "Handled in a separate hunt focused on MeshAgent and other RMM tools.",
            "status": "out_of_scope"
          },
          {
            "stage": "c2-protocol-tunneling",
            "reason": "Handled in a separate hunt focused on cloudflared and ngrok.",
            "status": "out_of_scope"
          },
          {
            "stage": "network-and-file-discovery",
            "reason": "Handled in a separate hunt focused on NetScan and nmap.",
            "status": "out_of_scope"
          },
          {
            "stage": "credential-dumping-ad",
            "reason": "Handled in a separate hunt focused on ntdsutil and mimikatz.",
            "status": "out_of_scope"
          },
          {
            "stage": "defense-evasion-tampering",
            "reason": "Handled in a separate hunt focused on Defender tampering.",
            "status": "out_of_scope"
          },
          {
            "stage": "lateral-movement-psexec-rdp",
            "reason": "Handled in a separate hunt focused on PsExec and batch-enabled RDP.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An intruder is exfiltrating staged directories and Active Directory database fragments using synchronization tools before deploying a ransomware payload for mass encryption.",
        "blind_spots": [
          {
            "id": "no-network-flow-logs",
            "risk": "A negative result does not prove exfiltration did not occur; it only proves it was not seen on the flow surface.",
            "stage": "exfiltration-cloud-storage",
            "question": "the total volume of data exfiltrated by a specific process",
            "requires": "hb_network_connection flow log provider (state_kind = log)"
          },
          {
            "id": "low-level-api-encryption",
            "risk": "Advanced ransomware may use drivers or low-level disk access to encrypt data without generating standard file activity rows.",
            "stage": "ransomware-impact",
            "question": "whether encryption is occurring via APIs that bypass standard activity logging",
            "requires": "kernel-level file monitor on every host"
          }
        ],
        "scoping_notes": "Focus on file servers and domain controllers where Storm-2570 frequently stages NTDS.dit files and conducts mass encryption.",
        "beyond_detection": "A standard rule might alert on rclone, but this hunt correlates process execution, attributed aggregate network volume via 5-tuple joins, and file system burst activity to provide the high-confidence context required for a critical isolation decision."
      }
    },
    {
      "id": "exfil-tool-execution",
      "type": "query",
      "label": "Exfiltration tool and staging activity",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE (instr(',' || '{{exfil_tools}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR LOWER(process_cmd_line) LIKE '%rclone%' OR LOWER(process_cmd_line) LIKE '%s5cmd%' OR LOWER(process_cmd_line) LIKE '%rdp.bat%' OR LOWER(process_cmd_line) LIKE '%ntds.dit%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Find the launch of synchronization tools or commands that stage the Active Directory database and RDP enablement scripts.",
        "expected_signal": "Hits identify the host, user, and specific staging or exfiltration tool used. Silence means no known synchronization or database staging binaries were seen."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "Exfiltration tool and staging activity",
        "reads": [
          "device_hostname",
          "process_name",
          "process_cmd_line",
          "user_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE (instr(',' || '{{exfil_tools}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR LOWER(process_cmd_line) LIKE '%rclone%' OR LOWER(process_cmd_line) LIKE '%s5cmd%' OR LOWER(process_cmd_line) LIKE '%rdp.bat%' OR LOWER(process_cmd_line) LIKE '%ntds.dit%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Hits identify the host, user, and specific staging or exfiltration tool used. Silence means no known synchronization or database staging binaries were seen.",
        "verified": "dry-run",
        "verified_at": "2026-09-25"
      }
    },
    {
      "id": "high-volume-outbound",
      "type": "query",
      "label": "High volume outbound traffic",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "network",
        "content": "SELECT e.device_hostname, e.process_name, SUM(f.traffic_bytes) AS total_bytes_sent FROM hb_network_connection e JOIN hb_network_connection f ON e.src_endpoint_ip = f.src_endpoint_ip AND e.src_endpoint_port = f.src_endpoint_port AND e.dst_endpoint_ip = f.dst_endpoint_ip AND e.dst_endpoint_port = f.dst_endpoint_port AND e.protocol = f.protocol WHERE e.state_kind = 'live' AND f.state_kind = 'log' AND f.direction = 'outbound' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || e.device_hostname || ',') > 0) AND f.time >= datetime('now', '-{{lookback_days}} days') GROUP BY e.device_hostname, e.process_name HAVING total_bytes_sent > 104857600",
        "surface": "hb_network_connection",
        "description": "Attribute network transfer volume to specific processes by joining endpoint socket states with flow logs.",
        "expected_signal": "A hit shows a process that has transferred over 100MB of data. Correlate these results with the exfiltration tools found in the lead query."
      },
      "parents": [
        {
          "id": "exfil-tool-execution"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "High volume outbound traffic",
        "reads": [
          "device_hostname",
          "process_name",
          "traffic_bytes",
          "state_kind",
          "direction",
          "src_endpoint_ip",
          "src_endpoint_port",
          "dst_endpoint_ip",
          "dst_endpoint_port",
          "protocol"
        ],
        "source": "hb_network_connection",
        "target": "network",
        "content": "SELECT e.device_hostname, e.process_name, SUM(f.traffic_bytes) AS total_bytes_sent FROM hb_network_connection e JOIN hb_network_connection f ON e.src_endpoint_ip = f.src_endpoint_ip AND e.src_endpoint_port = f.src_endpoint_port AND e.dst_endpoint_ip = f.dst_endpoint_ip AND e.dst_endpoint_port = f.dst_endpoint_port AND e.protocol = f.protocol WHERE e.state_kind = 'live' AND f.state_kind = 'log' AND f.direction = 'outbound' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || e.device_hostname || ',') > 0) AND f.time >= datetime('now', '-{{lookback_days}} days') GROUP BY e.device_hostname, e.process_name HAVING total_bytes_sent > 104857600",
        "silence": "not_evidence_of_absence",
        "expected": "A hit shows a process that has transferred over 100MB of data. Correlate these results with the exfiltration tools found in the lead query.",
        "verified": "dry-run",
        "verified_at": "2026-09-25"
      }
    },
    {
      "id": "file-impact-indicators",
      "type": "query",
      "label": "Ransomware file activity bursts",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, activity_name, COUNT(*) AS event_count, MIN(time) AS start_time, MAX(time) AS end_time FROM hb_file_activity WHERE activity_id IN (1, 3, 5) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND ('{{scope_processes}}' = '' OR instr(',' || '{{scope_processes}}' || ',', ',' || LOWER(process_name) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name, activity_name HAVING event_count > 500",
        "surface": "hb_file_activity",
        "description": "Identify processes that are performing mass file creations, modifications, or renames on the target hosts.",
        "expected_signal": "A hit shows a process modifying or renaming hundreds of files in a short window. This is the primary indicator of encryption."
      },
      "parents": [
        {
          "id": "exfil-tool-execution"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Ransomware file activity bursts",
        "reads": [
          "device_hostname",
          "process_name",
          "activity_id",
          "activity_name",
          "time"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, activity_name, COUNT(*) AS event_count, MIN(time) AS start_time, MAX(time) AS end_time FROM hb_file_activity WHERE activity_id IN (1, 3, 5) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND ('{{scope_processes}}' = '' OR instr(',' || '{{scope_processes}}' || ',', ',' || LOWER(process_name) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name, activity_name HAVING event_count > 500",
        "silence": "not_evidence_of_absence",
        "expected": "A hit shows a process modifying or renaming hundreds of files in a short window. This is the primary indicator of encryption.",
        "verified": "dry-run",
        "verified_at": "2026-09-25"
      }
    },
    {
      "id": "triage-impact",
      "type": "analytic",
      "label": "Evaluate impact and exfiltration",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "network"
        ],
        "context": [
          "exfil-tool-execution",
          "high-volume-outbound",
          "file-impact-indicators"
        ],
        "objective": "Determine if any host is exhibiting the combined indicators of exfiltration (high network volume from synchronization tools) and encryption (mass file modification bursts).",
        "description": "Synthesize the results from tool execution, network volume, and file activity to confirm a ransomware attack.",
        "max_iterations": 4,
        "expected_signal": "A per-host verdict that links the exfiltration process to the encryption activity.",
        "success_criteria": "A structured per-host verdict of malicious, suspicious, or benign citing process names and network metrics."
      },
      "parents": [
        {
          "id": "high-volume-outbound",
          "kind": "merge"
        },
        {
          "id": "file-impact-indicators",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-impact",
      "type": "checkpoint",
      "label": "Route on impact verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the agent determines malicious ransomware encryption is occurring on at least one host",
        "condition": "the agent determines malicious ransomware encryption is occurring on at least one host",
        "blind_spot": "no-network-flow-logs",
        "confidence": "high",
        "description": "Direct the workflow to immediate host isolation if malicious ransomware behavior is confirmed.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-impact"
        }
      ]
    },
    {
      "id": "isolate-host",
      "type": "action",
      "label": "Isolate host",
      "config": {
        "target": "endpoint",
        "description": "Halt further encryption and data exfiltration by isolating the compromised device.",
        "instructions": "Isolate the host immediately after confirming malicious file encryption activity. Collect the binaries identified in the triage step.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-impact",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "manual-review",
      "type": "task",
      "label": "Review suspicious impact evidence",
      "config": {
        "assignee": "analyst",
        "description": "Manually validate suspicious activity that did not trigger immediate isolation.",
        "instructions": "Review hosts with suspicious network volume or file event counts. Confirm if the associated process matches a known backup or development workflow."
      },
      "parents": [
        {
          "id": "route-on-impact",
          "branch": "default"
        },
        {
          "id": "route-on-impact",
          "branch": "on_unavailable"
        },
        {
          "id": "route-on-impact",
          "branch": "on_refutes"
        },
        {
          "id": "isolate-host"
        }
      ]
    },
    {
      "id": "remediation-cleanup",
      "type": "task",
      "label": "Remediation and evidence capture",
      "config": {
        "assignee": "analyst",
        "description": "Finalize the incident by identifying the specific ransomware variant and capturing evidence.",
        "instructions": "For isolated hosts, capture the ransomware binary and check for extensions matching Qilin, DragonForce, Anubis, or BERT. Document the exfiltration staging path."
      },
      "parents": [
        {
          "id": "manual-review"
        }
      ]
    }
  ]
}