Ransomware Intelligence

stormous

Ransomware group profile

60Victims
RussiaSource country
82Impact score
Also Known As
Stormous Virus

Description

Stormous is a pro-Russian cybercriminal group known for its ransomware attacks and data exfiltration, employing double extortion tactics. They primarily target organizations in the United States, Ukraine, and Europe, focusing on sectors such as government, healthcare, and telecommunications. The group operates under a Ransomware-as-a-Service model, enabling affiliates to utilize their tools extensively.

Key insights

  • Stormous employs double extortion tactics, encrypting and threatening to leak sensitive data.
  • Targets include government, healthcare, energy, and telecommunications sectors.
  • The group utilizes both custom and publicly available tools, often exploiting unpatched vulnerabilities.
  • They primarily operate through a Ransomware-as-a-Service (RaaS) model.
  • Recent attacks include significant data breaches affecting hundreds of thousands of individuals.
  • Stormous claims alignment with Russian geopolitical interests and focuses on Western countries.

Threat Level & Status Breakdown

For stormous · Based on incidents in selected period

3.9threat level
Aggressiveness10/ 10
Lethality0.3/ 10
Criticality1.1/ 10

Status Breakdown

Data Leaked5.0%3
Claimed5.0%3
First seenJul 2025
Last seenJun 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 23, 2026

Recent activity

Monthly attack count for stormous in the selected period

60Total attacks
20peak in Oct
7.5avg / month
↑ 10 vs first month
JulOctNovDecJanAprMayJun05101520

Intelligence

IOCs, YARA/Sigma rules, and related families for stormous

  1. b15a8047abd9a3af013cf6c77ce15acf
  2. 95ae81de52655fac3f1b226f1896690566090640
  3. 1b4b4e910bfd31f5f3f2f3a269bf2c994978b78a
  4. 8cee3ec87a5728be17f838f526d7ef3a842ce8956fe101ed247a5eb1494c579d
  5. f001329114937fbc439f251c803ba825
  6. 8ad67a1b7a5f2428c93f7a13a398e39c
  7. 0a73291ab5607aef7db23863cf8e72f55bcb3c273bb47f00edf011515aeb5894
  8. 2a720281cd869c1aaaca430a96cf980f623e0f76
  9. 12b818950d749c378aabd81a0bac9742
  10. e014c9e5f712775e771c7f36d2a580d8d290c9ad
  11. 96ba3ba94db07e895090cdaca701a922523649cf6d6801b358c5ff62416be9fa
  12. 8b758ccdfbfa5ff3a0b67b2063c2397531cf0f7b3d278298da76528f443779e9
  13. d4f71fc5479a02c8ff57c90fc67b948adb5604e0
  14. aa62afd6a48d3c42ed66d4f5b9189be847ec055b
  15. a1b468e9550f9960c5e60f7c52ca3c058de19d42eafa760b9d5282eb24b7c55f
  16. 3afd36e7e837d7216bdb48e466f8dcd5f2b169b6
View full IOC feed31 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for stormous

CVE-2023-47246
CVE-2023-46850
CVE-2023-46849
CVE-2023-46747
CVE-2023-46604
CVE-2023-34058
CVE-2023-34057
CVE-2023-34051
CVE-2023-34048
CVE-2023-23369
CVE-2023-23368
CVE-2023-22518
Other

T1486

T1486

T1490

T1490

T1078

T1078

T1021

T1021

T1562

T1562

T1059

T1059

T1547

T1547

T1021.001

T1021.001

T1210

T1210

T1005

T1005

T1105

T1105

T1041

T1041

Victims(60)

CompanyDomainCountryIndustryStatusDiscovered
maglificioliliana.commaglificioliliana.comIT Italy
Unknown
1 day ago
impulso-store.comimpulso-store.comMX MexicoRetail & E-Commerce
Unknown
1 day ago
lorenzoni-store.comlorenzoni-store.comIT ItalyRetail & E-Commerce
Unknown
1 day ago
montechiaro-store.commontechiaro-store.comIT ItalyRetail & E-Commerce
Unknown
1 day ago
jaggroup.com UPDATE-FULL DATA DUMPjaggroup.comUS United StatesProfessional Services
Unknown
4 days ago
mlit.com.my UPDATE-FULL DATA DUMP 10GBmlit.com.myMY MalaysiaGovernment & Defense
Data Leaked
6 days ago
mlit.com.mymlit.com.myMY MalaysiaGovernment & Defense
Data Leaked
13 days ago
katholiekamersfoort.nl UPDATE-FOR SALENL NetherlandsOther
Unknown
16 days ago
sa2000.com UPDATE-FULL DATA DUMPFinancial Services
Unknown
16 days ago
SA2000.COMsa2000.comSA Saudi ArabiaTechnology
Unknown
22 days ago
katholiekamersfoort.nlkatholiekamersfoort.nlNL NetherlandsEducation
Unknown
23 days ago
vspsolutions.com.au FULL DATA DUMPAU AustraliaProfessional Services
Unknown
about 1 month ago
Important Announcement
Unknown
about 1 month ago
VPN Access Sale
Unknown
about 1 month ago
cgcsa.co.za UPDATE-FULL DATA DUMPZA South AfricaProfessional Services
Unknown
about 1 month ago
vspsolutions.com.au SAMPLE-FREE 20GBvspsolutions.com.auAU AustraliaProfessional Services
Unknown
about 1 month ago
ttt.vn UPDATE-FULL DATA DUMPVN VietnamOther
Unknown
about 1 month ago
arc-reins.com + fidelityunited.ae UPDATE-FULL DATA DUMParc-reins.comAE United Arab EmiratesFinancial Services
Unknown
about 1 month ago
FANASA.COM UPDATE-FULL DATA DUMPMX MexicoFinancial Services
Unknown
about 1 month ago
ams-group.co.uk FULL DATA DUMP 33GBGB United KingdomProfessional Services
Unknown
about 2 months ago

Page 1 of 3