Contribution
This post adds original detection content: a two-boundary tripwire for Storm-2570's use of s5cmd and Rclone that joins endpoint execution to outbound object-storage traffic, then checks whether the destination belongs to the organisation. It also closes a common blind spot in cloud-led investigations: an upload to an attacker-owned bucket, authenticated with the attacker's AWS keys, will not normally leave a PutObject event in the victim's CloudTrail.
The pattern
Microsoft Threat Intelligence tracks Storm-2570 as a ransomware affiliate active since April 2025. The affiliate has deployed Qilin, DragonForce, Anubis and BERT ransomware, yet the work before encryption has stayed recognisable. Microsoft reports repeated use of remote management software, outbound tunnels, credential dumping, PsExec, s5cmd and Rclone across separate intrusions.
That distinction matters. A rule tied to one encryptor's hash or filename loses value when an affiliate changes ransomware service. The operator's quieter habits survive the change. Storm-2570 has used MeshAgent, Atera, NinjaRMM, ScreenConnect, Splashtop and Remotely_Agent for access. It has paired them with Cloudflare Tunnel or ngrok, harvested credentials with tools including Mimikatz, LaZagne, pypykatz and ntdsutil, moved through Windows estates with PsExec, Impacket or NetExec, and then copied selected business files to cloud storage.
Microsoft says initial access is unconfirmed for the activity it attributes to Storm-2570. That boundary should stay explicit. An investigation should not turn an unknown foothold into a claimed phishing campaign or vulnerability merely because either route is plausible.
Separate incident research helps test which parts of the chain recur beyond Microsoft's actor label. Huntress observed s5cmd in a Qilin intrusion after access through an exposed RDP instance. The attacker supplied a credentials file, selected document, image, spreadsheet and archive extensions, copied the files to an S3 bucket, then used PsExec to push ransomware. Huntress had seen a nearly identical s5cmd command five weeks earlier. Arctic Wolf Labs documented other Qilin intrusions with a confirmed PAN-OS vulnerability as the entry route, followed by remote-access tools, LSASS and NTDS credential theft, PsExec and, in some intrusions, exfiltration with Rclone or FileZilla, with MEGA as the main destination, before encryption.
Those reports do not prove that every Qilin case belongs to Storm-2570. They do show that the middle and late stages are reusable across affiliates: remote control, credential theft, lateral execution, bulk transfer and encryption. That is the useful defensive unit. Detect the sequence rather than betting response time on the payload name.
The transfer command is unusually helpful. Microsoft observed s5cmd.exe staged beside a credentials file and run with cp operations and extension filters to send selected data to attacker-controlled S3 buckets. Huntress published the same shape, with a literal s3:// destination: --credentials-file, several --include arguments and a local source copied to S3. A legitimate object-storage migration can look similar in isolation, so the executable name is not enough. The alert earns its value from destination ownership, execution context and the preceding host activity.
Why it matters to cloud defenders
s5cmd is a legitimate high-performance client for Amazon S3 and compatible object stores. Rclone is equally at home in backup and migration jobs. Blocking either name everywhere would break real work and still miss a renamed binary. Cloud defenders need to treat them as dual-use transfer clients and ask whether the process, identity, host, destination and timing fit an approved data movement path.
The destination creates an awkward split in visibility. AWS documents S3 PutObject activity as a CloudTrail data event, and notes that trails and event data stores do not log data events by default. More important here, CloudTrail is account-side telemetry. When an attacker runs s5cmd on a victim server with credentials for an attacker-controlled bucket, the useful S3 data event belongs to the destination account. The victim organisation is unlikely to receive it. Turning on data events for the victim's own buckets does not reveal uploads into somebody else's account.
The victim still owns the source-side evidence. Endpoint telemetry can record process creation, the command line, parent process, account and path. Network telemetry can associate the process with an S3 hostname, an S3-compatible endpoint or another cloud-storage service. A proxy or firewall may add bytes sent, TLS server name and destination category. File telemetry may record a newly dropped s5cmd.exe, rclone.exe, configuration file or credentials file. None of those fields alone says 'ransomware affiliate', but together they can identify an unapproved export while the attacker is still copying data.
Cloud-hosted Windows workloads make this more urgent. File servers, jump hosts and domain controllers running in AWS, Azure or GCP often have permissive internet egress because administrators need package repositories and management services. The exfiltration process may use static credentials supplied by the attacker, not the VM's workload identity. Looking only at the instance role's CloudTrail activity, an Azure managed identity's sign-ins or GCP service-account calls misses that route.
The opposite case also matters. If the command uses credentials owned by the victim organisation, CloudTrail may show PutObject, provided S3 data-event logging covers the destination bucket. That gives the SOC a second boundary to inspect. It does not remove the need for host evidence, because data events are optional and a sanctioned bucket can still be abused as a staging point.
Treat destination ownership as an enrichment field, not a manual question left for incident response. Maintain an allowlist of approved bucket names, account IDs, object-storage endpoints and transfer identities. Extract the destination from command lines where possible. Flag a transfer from a sensitive server when the bucket is unknown, the endpoint is outside the approved set, or the process uses an explicit credentials file that is not part of the server's normal job configuration.
ATT&CK mapping
The observed chain begins after an unconfirmed entry point, so assigning an Initial Access technique to Storm-2570 would overstate the evidence. The first reliable stage is command and control through remote management software, which maps to Remote Access Tools (T1219). MeshAgent, Atera, ScreenConnect and similar products can be legitimate, making inventory and execution context more useful than product-name blocking.
Credential theft follows. Microsoft's ntdsutil activity and Arctic Wolf's Install From Media command map to OS Credential Dumping: NTDS (T1003.003). That stage changes the response scope. Once the domain database has been copied, stopping one RMM process does not contain the incident; defenders need to treat domain credentials as exposed and trace their subsequent use.
The data payoff is Exfiltration to Cloud Storage (T1567.002). s5cmd cp to an S3 destination and Rclone synchronisation to cloud storage fit the technique directly. MITRE ATT&CK describes T1567.002 as sending data to a cloud-storage service rather than through the main command channel. The behaviour can blend with normal backup traffic, which is why process lineage and destination ownership are central to detection.
The impact stage is Data Encrypted for Impact (T1486). This is the technique listed in the article metadata because a13e already has a hand-authored T1486 technique page. The earlier techniques remain in the chain and in this analysis, but they are not added to metadata merely to create thin library pages.
This ordering provides two chances to act before encryption. Remote-tool proliferation and NTDS extraction are early warnings. A bulk cloud transfer is a late but valuable tripwire because it can precede ransomware deployment. The transfer should not be dismissed as 'only exfiltration' while containment waits for an encryptor alert.
Detection guidance
Start with process creation on Windows servers. The query below uses Microsoft Defender XDR's documented DeviceProcessEvents fields and looks for object-storage transfer syntax. It is deliberately behavioural: it catches the expected filenames, but it also catches a renamed process whose command line still carries --credentials-file, an s3:// copy, or Rclone's copy, sync and move verbs. Rclone destinations are usually written as remote:bucket from a config file rather than as s3://, so the query does not require an S3 URI. Native Defender advanced hunting covers the past 30 days, which sets the lookback. The precursor table is scoped to devices that ran a transfer and bucketed to the minute, so noisy RMM command lines do not multiply the join.
let TransferExecutions =
DeviceProcessEvents
| where Timestamp > ago(30d)
| where (FileName in~ ("s5cmd.exe", "rclone.exe")
and ProcessCommandLine has_any ("cp", "copy", "sync", "move"))
or ProcessCommandLine contains "--credentials-file"
or ProcessCommandLine matches regex @"(?i)\brclone(?:\.exe)?""?\s+(copy|sync|move)\b"
or (ProcessCommandLine contains "s3://"
and ProcessCommandLine has_any ("cp", "mv", "sync"))
| project UploadTime=Timestamp, DeviceId, DeviceName, AccountName,
FileName, FolderPath, ProcessCommandLine, InitiatingProcessFileName;
let Devices = TransferExecutions | distinct DeviceId;
let Precursors =
DeviceProcessEvents
| where Timestamp > ago(30d) and DeviceId in (Devices)
| where FileName in~ ("psexec.exe", "psexec64.exe", "ntdsutil.exe", "ngrok.exe", "cloudflared.exe")
or ProcessCommandLine has_any ("meshagent", "meshcentral", "DisableRealtimeMonitoring", "DisableAntiSpyware")
| summarize by DeviceId, PrecursorTime=bin(Timestamp, 1m),
PrecursorFile=FileName, PrecursorCommand=ProcessCommandLine;
TransferExecutions
| join kind=leftouter Precursors on DeviceId
| extend PrecursorInWindow = isnotnull(PrecursorTime)
and PrecursorTime between (UploadTime - 24h .. UploadTime)
| summarize Precursors=make_set_if(strcat(PrecursorFile, ": ", PrecursorCommand), PrecursorInWindow, 20)
by UploadTime, DeviceId, DeviceName, AccountName, FileName, FolderPath,
ProcessCommandLine, InitiatingProcessFileName
| order by UploadTime desc
Run the query as a hunt first. Turn it into an alert after adding local context: approved transfer hosts, service accounts, install paths, parent processes, bucket prefixes and maintenance windows. Do not exclude s5cmd.exe or Rclone globally. A scheduled backup from a known server to a registered bucket, launched by the expected service account from a managed path, is different from an interactive administrator session running a newly downloaded binary from C:\PerfLogs or a temporary directory.
Add a network check for every hit. In Defender XDR, DeviceNetworkEvents exposes RemoteUrl, RemoteIP, InitiatingProcessFileName, InitiatingProcessCommandLine and the device identifier. Join on DeviceId and a tight time window around UploadTime. Look for S3 regional endpoints, virtual-hosted bucket names and custom S3-compatible endpoints. Rclone can also send to non-S3 services such as MEGA, so treat any unfamiliar cloud-storage destination from a server as in scope. Proxy and firewall products may provide upload byte counts, which can raise priority when a file server sends a sustained volume to a destination it has never contacted.
Then classify the destination. Parse the bucket or endpoint from the command line and compare it with the organisation's registry of approved storage. If the destination is in an owned AWS account, query CloudTrail for S3 data events and verify the principal, source IP, bucket and object prefix. If no data event exists, first confirm that data-event logging covers the bucket. AWS states that the default CloudTrail setting captures management events, not S3 object-level activity.
If the bucket is external or ownership cannot be established, absence from CloudTrail is expected rather than reassuring. Preserve the endpoint process event, command line, DNS and proxy records, and any copy of the credential file without printing secrets into a ticket. The explicit credentials file is a strong investigation pivot: record its creation time, path, file owner and the process that wrote it. Rotate credentials only after identifying whether they belong to the victim, because attacker-owned keys cannot be revoked by the victim and should instead be preserved as evidence.
Raise severity when the same device shows any of these precursors within 24 hours: a new RMM service, Cloudflare Tunnel or ngrok running as LocalSystem, PsExec fan-out, ntdsutil creating an IFM copy, Defender protection changes, or broad network-share enumeration. Lower severity only when destination ownership, job schedule, identity and process lineage all match a registered transfer workflow.
What to do now
Inventory approved bulk-transfer tools and destinations. Record the executable path, service account, parent process, bucket or endpoint, expected source directories and schedule. Include S3-compatible storage rather than limiting the list to AWS hostnames.
Run the process query across file servers, domain controllers, backup hosts and administrative jump boxes. Review hits with
--credentials-file, many--includefilters, local or UNC sources, and destinations outside the approved registry. Hunt for renamed copies by command-line shape and original-file metadata where available.Join each hit to remote-access, tunnel, credential-dumping and Defender-tampering activity. A transfer following MeshAgent, PsExec or
ntdsutildeserves incident handling even if the destination uses a common cloud domain and no ransomware binary has appeared.Test the cloud evidence boundary. For owned buckets, confirm that CloudTrail S3 data events cover the prefixes that receive bulk uploads and reach the SIEM. For external buckets, make sure endpoint and network retention can carry the investigation because the victim will not control the destination logs.
Contain by sequence, not payload. Isolate affected hosts, disable unauthorised RMM and tunnel services, stop active transfer processes, block confirmed external destinations, and reset exposed domain credentials. Preserve command lines, transfer configuration and network records before cleanup. Do not wait for Qilin, DragonForce, Anubis or BERT detection to prove the operator's identity.
Storm-2570's payload switching is the distraction. The dependable signal is a privileged Windows host moving from remote control and credential theft into an object-storage client that points somewhere the organisation does not own. That boundary can be monitored now, and it arrives before encryption does.