Stormous is a cybercriminal ransomware and data-extortion group known for publicly naming victims and advertising stolen data from organizations in multiple countries. Its operations have targeted commercial enterprises and public-sector entities, including manufacturing, consumer-facing businesses, and government-related organizations. Reported victims span the United States, Italy, Malaysia, Japan, the Netherlands, the United Kingdom, Sweden, Tunisia, Mexico, and other countries. Observed Stormous activity is characterized by ransomware claims combined with theft and public exposure of victim data. The group has repeatedly asserted access to internal corporate systems and business records, including financial documents, customer and employee information, operational files, backups, directory listings, and credential material. In several cases it has published or threatened publication of full data dumps, used time-limited pressure such as grace periods before release, and framed incidents as negotiable, indicating an extortion-driven model. The available reporting supports data-theft extortion and leak-site style victim shaming; ransomware branding is consistently present, but the supplied facts emphasize exfiltration and coercive disclosure more strongly than confirmed encryption behavior. Stormous has been linked to intrusions involving unauthorized access to internal servers, network shares, remote desktop-related data, enterprise business applications, backup repositories, and credential-containing datasets. Across reported incidents, the group demonstrated capabilities consistent with initial access, credential theft, exfiltration, post-exploitation, and extortion. Its victimology indicates opportunistic targeting across sectors rather than a narrowly specialized vertical focus. High-confidence attribution of a specific state sponsor or national origin is not currently available from the supplied facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
14 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only in related content as a separate cybercrime gang previously claiming a Coca-Cola breach.
Related Posts ... Stormous ATTACKS Swedish University
Conducting a ransomware/data extortion attack against HIGUCHI INC., claiming unauthorized access across three branches and threatening to leak 102 GB of backups and commercial/personal data within an 8-day grace period.
Claimed compromise of Palatine School infrastructure, alleging full access to the central server and sensitive student and staff records, while stating they would not leak data and would instead disclose vulnerabilities to the school.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.