Stormous ransomware group
Threat Actor
Stormous gained some attention at the beginning of 2022 when it said they stole 200 GB of data from Epic Games. They have sought to make its name by taking advantage of the rising tensions between Russia and Ukraine.
On Feb. 24, 2024, Stormous group mentioned on “The Five Families” Telegram channel that they have started their new ransomware-as-a-service (RaaS) program “STMX_GhostLocker” along with their partners in GhostSec. The new program is made up of three categories of services for the affiliates: paid, free, and another for the individuals without a program who only want to sell or publish data on their blog (PYV service).
Incidents Associated with this Threat
- March 6, 2024: Belgian Duvel Brewery Halts Production after Ransomware Attack.
- January 7, 2024: Ransomware Attack at Indonesian Railway company
- April 24, 2022: Coca-Cola Hit in Cyberattack
Malware Used by this Threat Actor
No malware identified for this threat actor.
