Ransomware Intelligence

stormous

Ransomware group profile

56Victims
RussiaSource country
71Impact score
Also Known As
Stormous Virus

Description

Stormous is a pro-Russian cybercriminal group known for its ransomware attacks and data exfiltration, employing double extortion tactics. They primarily target organizations in the United States, Ukraine, and Europe, focusing on sectors such as government, healthcare, and telecommunications. The group operates under a Ransomware-as-a-Service model, enabling affiliates to utilize their tools extensively.

Key insights

  • Stormous employs double extortion tactics, encrypting and threatening to leak sensitive data.
  • Targets include government, healthcare, energy, and telecommunications sectors.
  • The group utilizes both custom and publicly available tools, often exploiting unpatched vulnerabilities.
  • They primarily operate through a Ransomware-as-a-Service (RaaS) model.
  • Recent attacks include significant data breaches affecting hundreds of thousands of individuals.
  • Stormous claims alignment with Russian geopolitical interests and focuses on Western countries.

Threat Level & Status Breakdown

For stormous · Based on incidents in selected period

2.6threat level
Aggressiveness6/ 10
Lethality0.2/ 10
Criticality1.4/ 10

Status Breakdown

Data Leaked3.6%2
Claimed14.3%8
First seenJun 2025
Last seenJun 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 2, 2026

Recent activity

Monthly attack count for stormous in the selected period

56Total attacks
20peak in Oct
6.2avg / month
↓ 5 vs first month
JunJulOctNovDecJanAprMayJun05101520

Intelligence

IOCs, YARA/Sigma rules, and related families for stormous

  1. b15a8047abd9a3af013cf6c77ce15acf
  2. 0a73291ab5607aef7db23863cf8e72f55bcb3c273bb47f00edf011515aeb5894
  3. 96ba3ba94db07e895090cdaca701a922523649cf6d6801b358c5ff62416be9fa
  4. aa62afd6a48d3c42ed66d4f5b9189be847ec055b
View full IOC feed10 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for stormous

CVE-2023-47246
CVE-2023-46850
CVE-2023-46849
CVE-2023-46747
CVE-2023-46604
CVE-2023-34058
CVE-2023-34057
CVE-2023-34051
CVE-2023-34048
CVE-2023-23369
CVE-2023-23368
CVE-2023-22518
Other

T1486

T1486

T1490

T1490

T1078

T1078

T1021

T1021

T1562

T1562

T1059

T1059

T1547

T1547

T1021.001

T1021.001

T1210

T1210

T1005

T1005

T1105

T1105

T1041

T1041

Victims(56)

CompanyDomainCountryIndustryStatusDiscovered
katholiekamersfoort.nlkatholiekamersfoort.nlNL NetherlandsEducation
Unknown
1 day ago
vspsolutions.com.au FULL DATA DUMPAU AustraliaProfessional Services
Unknown
11 days ago
Important Announcement
Unknown
17 days ago
VPN Access Sale
Unknown
17 days ago
cgcsa.co.za UPDATE-FULL DATA DUMPZA South AfricaProfessional Services
Unknown
17 days ago
vspsolutions.com.au SAMPLE-FREE 20GBAU AustraliaProfessional Services
Unknown
21 days ago
ttt.vn UPDATE-FULL DATA DUMPVN VietnamOther
Unknown
21 days ago
FANASA.COM UPDATE-FULL DATA DUMPMX MexicoFinancial Services
Unknown
23 days ago
arc-reins.com + fidelityunited.ae UPDATE-FULL DATA DUMPAE United Arab EmiratesFinancial Services
Unknown
23 days ago
ams-group.co.uk FULL DATA DUMP 33GBGB United KingdomProfessional Services
Unknown
25 days ago
ttt.vn TTT Corporationttt.vnVN VietnamOther
Unknown
29 days ago
or-technology.comor-technology.comDE GermanyTechnology
Unknown
about 1 month ago
cgcsa.co.zacgcsa.co.zaZA South AfricaRetail & E-Commerce
Unknown
about 1 month ago
FANASA.COMfanasa.comMX MexicoHealthcare
Unknown
about 1 month ago
arc-reins.com + fidelityunited.aefidelityunited.aeAE United Arab EmiratesFinancial Services
Unknown
about 1 month ago
GhostLocker/Stm
Claimed
about 2 months ago
Clarochileclarochile.clCL Chile
Unknown
4 months ago
GOODMANMFGManufacturing
Unknown
6 months ago
futurealOther
Unknown
6 months ago
bkcolombiaCO ColombiaOther
Unknown
6 months ago

Page 1 of 3