Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors stormous

Description

Stormous is an Arabic-speaking, pro-Russian ransomware and hacktivist group active since at least 2022, known for politically motivated attacks across 15+ countries, collaborating with GhostSec on the GhostLocker 2.0 RaaS platform and inheriting GhostSec's RaaS operations in mid-2024. Known victims: 169

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Stormous is a medium-sophistication criminal threat actor group that combines hacktivist activities with ransomware operations, likely aligned with pro-Russian ideologies. Known since at least March 2022, the group has conducted politically motivated attacks across more than 15 countries and operates the GhostLocker 2.0 Ransomware-as-a-Service (RaaS) platform in collaboration with GhostSec. Stormous primarily targets organizations for financial gain through ransomware deployment, frequently sharing indicators of compromise (IOCs) on leak sites following breaches.

Goals & Targeting

Stormous' strategic objectives align closely with financial gain through ransomware deployment, while its hacktivist elements suggest an interest in targeting entities that could yield both monetary rewards and political influence. The group's selection of victims appears to be driven by ease of access, sector vulnerabilities, and potential for high-value data dumps. Primarily targeting the corporate and public sectors across multiple countries, Stormous demonstrates a preference for organizations with weaker cybersecurity postures. Their focus on the Middle East, North Africa, Europe, and parts of Asia may reflect both operational opportunities and ideological leanings.

Enhanced Description

Stormous is an Arabic-speaking cybercriminal group that emerged as a significant threat in early 2022 and has since expanded its operations globally. The group is known for its dual focus: hacktivist-style attacks with potential political motivations and overt ransomware campaigns targeting businesses and organizations for financial gain. Operating under a Ransomware-as-a-Service (RaaS) model through the GhostLocker platform, Stormous demonstrates moderate technical proficiency, leveraging existing infrastructure such as bulletproof hosting and fast-flux domains to maintain operational stealth. The group's collaboration with GhostSec suggests strategic shifts in leadership or operations, potentially indicating an evolution in its tactics following the decommissioning of GhostSec's activities earlier in 2024. Stormous' victims span multiple sectors, including technology, healthcare, education, and retail, with notable campaigns involving extensive data dumps on platforms like Pastebin and other leak sites. The group's use of politically motivated attacks may indicate a broader agenda beyond mere financial gain, though their primary motivation remains profit.

Key Capabilities

  • Ransomware deployment (including GhostLocker variants)
  • Phishing campaigns using spear-phishing emails
  • Malicious Office document distribution
  • Use of Ransomware-as-a-Service platforms
  • Data exfiltration and leak site activity
  • Potential use of tools like Cobalt Strike or custom C2 frameworks

MITRE ATT&CK Tactics

Reconnaissance
Initial Access
Execution
Persistence
Credential Access
Discovery
Lateral Movement
Exfiltration
Impact

ATT&CK Techniques

T1043.004 - Adversary Scripting: VBA Macros in Documents
T1566.002 -Credential Dumping Tools: LSASS Memory Dumps
T1078.001 - Email Collection: Phishing for Credentials via Email
T1093.001 - Valid Accounts: Account Access Removal or Modification
T1544.004 - Network-Based File Transfer Tools: Encrypted ZIP
T1218 - Web Service

Software / Tooling

GhostLocker Ransomware
Spear-phishing Kits
Cobalt Strike (potential)
Mimikatz (for credential dumping)
Custom Malware/Droppers
Bulletproof Hosting Services
Fast-flux Domain Infrastructure

Campaigns & Victims

Stormous has demonstrated a consistent operational tempo, frequently targeting businesses and public sector entities. Notable campaigns include the full data dumps of victims such as or-technology.com, FANASA.COM, and others, indicating both financial and reputational damage intent. The group's ability to collaborate with other threat actors like GhostSec suggests an organized approach to maintaining their RaaS operations. Their shift in focus to GhostLocker 2.0 mid-2024 may indicate efforts to refine their toolset, improve evade detection, or expand their operational reach.

IOC Patterns

  • Spear phishing emails with malicious Office document attachments
  • Malware distribution via compromised websites or direct delivery
  • C2 communication over HTTPS and fast-flux domains
  • Exfiltration of data to leak sites post-encryption
  • Encrypted backups, files, or systems with specific ransom notes
  • Use of known RaaS platforms for affiliate recruitment

Recommended Actions

  • Implement strict email filtering policies to block phishing emails and macro-laced documents.
  • Monitor for malicious VBA scripts in Office attachments using endpoint detection tools.
  • Regularly update software and patch systems to mitigate potential exploit usage.
  • Segment critical data from general network access to limit lateral movement.
  • Use multi-factor authentication for all critical accounts.
  • Conduct regular training sessions on phishing awareness for employees.
  • Monitor dark web platforms and leak sites for indicators of compromise.

Suggested Tags

Ransomware
Hacktivist
Criminal Group
Pro-Russian
Financial-Gain
Geopolitical

Confidence Assessment

The information on Stormous is derived from open-source intelligence and media reports, suggesting a moderate confidence level. While the group's operational timeline and key activities are well-documented, specific technical details about their TTPs and exact toolset remain limited. High-confidence data gaps include precise tools used in campaigns, definitive sector targeting criteria beyond general observations, and an understanding of the underlying infrastructure specifics.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

25

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Hacktivism
Hacktivist
Criminal Group
Pro-Russian
Financial-Gain
Geopolitical

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Mar 22, 2022
Last Seen
Jul 1, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.