Stormous is an Arabic-speaking, pro-Russian ransomware and hacktivist group active since at least 2022, known for politically motivated attacks across 15+ countries, collaborating with GhostSec on the GhostLocker 2.0 RaaS platform and inheriting GhostSec's RaaS operations in mid-2024. Known victims: 169
Objectives
Executive Summary
Stormous is a medium-sophistication criminal threat actor group that combines hacktivist activities with ransomware operations, likely aligned with pro-Russian ideologies. Known since at least March 2022, the group has conducted politically motivated attacks across more than 15 countries and operates the GhostLocker 2.0 Ransomware-as-a-Service (RaaS) platform in collaboration with GhostSec. Stormous primarily targets organizations for financial gain through ransomware deployment, frequently sharing indicators of compromise (IOCs) on leak sites following breaches.
Goals & Targeting
Stormous' strategic objectives align closely with financial gain through ransomware deployment, while its hacktivist elements suggest an interest in targeting entities that could yield both monetary rewards and political influence. The group's selection of victims appears to be driven by ease of access, sector vulnerabilities, and potential for high-value data dumps. Primarily targeting the corporate and public sectors across multiple countries, Stormous demonstrates a preference for organizations with weaker cybersecurity postures. Their focus on the Middle East, North Africa, Europe, and parts of Asia may reflect both operational opportunities and ideological leanings.
Enhanced Description
Stormous is an Arabic-speaking cybercriminal group that emerged as a significant threat in early 2022 and has since expanded its operations globally. The group is known for its dual focus: hacktivist-style attacks with potential political motivations and overt ransomware campaigns targeting businesses and organizations for financial gain. Operating under a Ransomware-as-a-Service (RaaS) model through the GhostLocker platform, Stormous demonstrates moderate technical proficiency, leveraging existing infrastructure such as bulletproof hosting and fast-flux domains to maintain operational stealth. The group's collaboration with GhostSec suggests strategic shifts in leadership or operations, potentially indicating an evolution in its tactics following the decommissioning of GhostSec's activities earlier in 2024. Stormous' victims span multiple sectors, including technology, healthcare, education, and retail, with notable campaigns involving extensive data dumps on platforms like Pastebin and other leak sites. The group's use of politically motivated attacks may indicate a broader agenda beyond mere financial gain, though their primary motivation remains profit.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Stormous has demonstrated a consistent operational tempo, frequently targeting businesses and public sector entities. Notable campaigns include the full data dumps of victims such as or-technology.com, FANASA.COM, and others, indicating both financial and reputational damage intent. The group's ability to collaborate with other threat actors like GhostSec suggests an organized approach to maintaining their RaaS operations. Their shift in focus to GhostLocker 2.0 mid-2024 may indicate efforts to refine their toolset, improve evade detection, or expand their operational reach.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The information on Stormous is derived from open-source intelligence and media reports, suggesting a moderate confidence level. While the group's operational timeline and key activities are well-documented, specific technical details about their TTPs and exact toolset remain limited. High-confidence data gaps include precise tools used in campaigns, definitive sector targeting criteria beyond general observations, and an understanding of the underlying infrastructure specifics.
No techniques linked yet.
No tools linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
25
Campaigns
0
IOCs
0
Observed Data
0
Tactics