Stormous is an Arabic-speaking, pro-Russian ransomware and hacktivist group active since at least 2022, known for politically motivated attacks across 15+ countries, collaborating with GhostSec on the GhostLocker 2.0 RaaS platform and inheriting GhostSec's RaaS operations in mid-2024.
On 1st July 2026 the group has annonced the end of their operations & ervices
Command and Scripting InterpreterCommand and Scripting Interpreter: Visual BasicUser Execution: Malicious File
Persistence
Scheduled Task/JobAccount ManipulationServer Software Component: Web ShellCreate or Modify System Process: Windows ServiceBoot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Privilege Escalation
Abuse Elevation Control Mechanism: Bypass UAC
Defense Evasion
Obfuscated Files or InformationObfuscated Files or Information: Software PackingObfuscated Files or Information: Fileless StorageObfuscated Files or Information: Encrypted/Encoded FileIndicator RemovalImpair Defenses: Disable or Modify Tools
Credential Access
OS Credential Dumping
Discovery
Network Service DiscoveryFile and Directory Discovery
www.higuchi-inc.co.jp/newsrelease/company/doc/unauthorized_access_incident.pdf // We have reviewed the report issued by HIGUCHI INC. To correct their mistake: the breach...
Deep access to Microsoft Dynamics GP containing complete corporate accounting, invoices, vendor details, and commercial transactions.Access to internal legal documents, p...
We have breached ESHA Research / ESHA Cloud Services and compromised their core product development databases. The exfiltrated data includes highly confidential industry...
During our routine network security audits, our team discovered critical structural vulnerabilities within Palatine School, which granted us full, unrestricted access to...
Over 400 GB of data has been accessed and exfiltrated. This includes product designs, historical fashion lines, and technical specifications for garments. Furthermore, we...
Complete data belonging to customers and buyers has been accessed, along with designs, orders, and other assets. This includes all domains associated with the parent comp...
Complete data belonging to customers and buyers has been accessed, along with designs, orders, and other assets. This includes all domains associated with the parent comp...
Complete data belonging to customers and buyers has been accessed, along with designs, orders, and other assets. This includes all domains associated with the parent comp...
Full database containing corporate emails (@jaggroup.com), Active Directory domain logins, and clear plain-text passwords.Complete Microsoft Dynamics GP databases, soft...
We have successfully breached the internal servers and network infrastructure of MLIT, gaining full unauthorized access to their active Microsoft Dynamics Management Repo...
The church website's network (katholiekamersfoort.nl/) has been breached, resulting in the exfiltration of over 10 GB of data. This data pertains to donors, staff, and th...
$900k to Solve the Problem 5TB — While TTT Company was preoccupied with designing luxurious interiors and architectural masterpieces, they completely overlooked the desig...
We have gained full control over 700 GB of data, which includes: meticulous compliance audit data, complete Bank details for ARC, legal licenses, tax documents, and offic...
The extracted data comprises administrative and financial records, payroll sheets, and client and partner directories, alongside technical and engineering specifications,...
$900k to Solve the Problem 5TB — While TTT Company was preoccupied with designing luxurious interiors and architectural masterpieces, they completely overlooked the desig...
endor & Corporate Data ( Name-Email-Numbers/PMS NAME ), Financial Accounting Records , sales Order Reports , Database Systems , SQL Server , Sage 200 Evolutuion SQL, oper...
We have gained full control over 700 GB of data, which includes: meticulous compliance audit data, complete Bank details for ARC, legal licenses, tax documents, and offic...