stormous

Ransomware
Origin🇷🇺 Rússia
Sourceransomware.live

About the group

Stormous is an Arabic-speaking, pro-Russian ransomware and hacktivist group active since at least 2022, known for politically motivated attacks across 15+ countries, collaborating with GhostSec on the GhostLocker 2.0 RaaS platform and inheriting GhostSec's RaaS operations in mid-2024. On 1st July 2026 the group has annonced the end of their operations & ervices

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Impact and victims

The group stormous has 7 known ransomware victims. See the most affected sectors and countries and recent victims.

7known victims
7in Brazil
6sectors hit
Most attacked sectors
Professional Services2
Education1
Financial Services1
Manufacturing1
Technology1
Transportation1
Most affected countries
🇧🇷 Brasil7
Recent victims
rinaldi.com.brProfessional Services · BR · 2025-06-06
everplastManufacturing · BR · 2024-03-04
uffs.edu.brEducation · BR · 2024-01-18
InterepTransportation · BR · 2023-09-23
SeniorProfessional Services · BR · 2023-07-17
LINXTechnology · BR · 2023-03-27
CESCEFinancial Services · BR · 2023-03-25

stormous uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →