First Seen: 2021
Targeted Regions: United States, United Kingdom, Spain, France, Italy, Malaysia, United Arab Emirates, China, Brazil, India, Argentina, Turkey, Indonesia, Germany, Vietnam, Japan, Thailand, Uzbekistan, Iran, Lebanon, Colombia, Poland, South Africa, Taiwan, Tanzania, Tunisia, Bolivia, Canada, Cuba, Australia, Philippines, Denmark, Netherlands, Morocco, Portugal, Egypt, Croatia, Serbia, Belarus, Singapore, Mexico, Hungary, Bulgaria, South Korea, North Macedonia, Belgium, Greece, Switzerland, Saudi Arabia, Estonia, Mozambique
Targeted Industries: Technology, Business Services & Consulting, Manufacturing, Retail, Hospitality, Education, Healthcare, Telecommunications, Media, Government, Financial Services, Pharmaceutical, Energy, Transportation, Casino & Gambling, Aerospace and Defense, Food Service, Religion, Agriculture, Real Estate, Aviation, Insurance
Malware: StormousX
Threat Actor: Stormous
Attack: Stormous is an Arabic-speaking double-extortion group active since 2021 that gains access through unpatched internet-facing systems, phishing, and weak MFA, then leaks stolen data via a Tor site and Telegram, often without deploying encryption. Trackers record between 179 and 240 claimed victims across manufacturing, education, technology, finance, and healthcare, with the UAE, Brazil, Italy, the US, and the UK most affected, though only a few incidents are independently corroborated and past proofs have included recycled public data. In early July 2026 the group announced it would terminate operations, and all tracked leak-site mirrors are currently offline. Stormous is best assessed as an opportunistic, reputation-driven data-extortion actor whose claims warrant low confidence until victim-confirmed.
Attack Details
Recommendations
Enforce phishing-resistant multi-factor authentication on all remote access, including VPN, RDP and cloud consoles, and eliminate exception accounts. Audit for exposed or reused credentials in infostealer logs and past breach corpora. Rotate service and administrative passwords on a defined cycle and alert on logins from unfamiliar geographies or hosting providers.
Because encryption is uncommon in Stormous incidents, detection should target data movement rather than ransomware execution. Baseline outbound traffic and alert on large transfers to consumer file-hosting services such as mega.nz and gofile.io. Apply data loss prevention and egress filtering to finance, ERP, email archive and backup systems.
Keep immutable or offline backups and rehearse restoration, since the operation still threatens encryption under its double-extortion model.
Isolate internet-facing servers from identity infrastructure and business-critical data stores to limit how far an initial compromise can spread before detection.
On suspicion of compromise, isolate rather than rebuild affected systems and preserve logs and authentication artefacts, because attackers typically dwell for weeks before discovery.
Potential MITRE ATT&CK TTPs
Indicators of Compromise (IOCs)
| Type | Value |
|---|---|
| TOR Address | 3slz4povugieoi3tw7sblxoowxhbzxeju427cffsst5fo2tizepwatid[.]onion,h3reihqb2y7woqdary2g3bmk3apgtxuyhx4j2ftovbhe3l5svev7bdyd[.]onion,pdcizqzjitsgfcgqeyhuee5u6uki6zy5slzioinlhx6xjnsw25irdgqd[.]onion,6sf5xa7eso3e3vk46i5tpcqhnlayczztj7zjktzaztlotyy75zs6j7qd[.]onion,zib7duoiglvzvnpjs5faly6bio4xhwiby2lupsnxrkjnx46gmwdfyrid[.]onion,ahb6hjhe4nomgfwxequu52hazigh4ty4gdcnrf3r7z5tiyhour5py2id[.]onion,stniiomyjliimcgkvdszvgen3eaaoz55hreqqx6o77yvmpwt7gklffqd[.]onion,5pbckbo5ra36srfwmb2y6mqpqj7akx3e6ewanujszv7nnjndbbgsjsad[.]onion |
Recent Breaches
- higuchi-inc.co.jp
- higuchi-usa.com
- eogb.co.uk
- eshacloudqa.com
- monoprix.tn
- palatineschool.org
- maglificioliliana.com
- lorenzoni-store.com
- montechiaro-store.com
- impulso-store.com
- jaggroup.com
- mlit.com.my
- vspsolutions.com.au
- sa2000.com
- katholiekamersfoort.nl
References
- kelacyber.com — Stormous extortion group strikes back
- zensec.ae — Stormous ransomware
- blog.talosintelligence.com — GhostSec GhostLocker 2.0 ransomware
What Next?
At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.
