Skip to content

Stormous

Stormous is a PHP-based malware family associated with the Stormous ransomware operation.

Profile source: Mallory opens in a new tab

Stormous

Family profile

Stormous is a PHP-based malware family associated with the Stormous ransomware operation. It has been described as unusual among ransomware tooling because it combines backdoor functionality with file-encryption and ransom-note deployment, allowing operators to obtain remote access to compromised servers and then deliver additional custom payloads. Reported capabilities include malware dropping, remote access for follow-on activity, and ransomware execution.

Stormous has been publicly aligned with pro-Russian messaging during the Russia-Ukraine conflict and declared intent to target Ukrainian government institutions. Analysis has linked the operation to Arabic-speaking actors, likely from North Africa. The malware has been characterized as rapidly modifiable, reflecting its PHP implementation and use against web-facing environments.

Targeting has focused on web servers and vulnerable web applications running PHP. Stormous is primarily known as part of a ransomware and extortion operation rather than a commodity malware family, and it has appeared in multiple ransomware activity rankings and leak-site tracking during 2023 and 2025. The group has also operated a data leak site and, in some periods, relied on Telegram for victim disclosures and extortion-related publicity.

Capabilities

  • Exfiltration
  • Post Exploitation

Operational record

1
YARA rules
4
Leak sites
0 available

Reported operators

Threat actors

1 named in public reporting
Stormous

Stormous is one of the few exceptions. Aside from being a backdoor, it also contains ransomware functionality.

MITRE ATT&CK

Stormous in ATT&CK

35 distinct techniques

Reporting

Research mentioning Stormous

Aug 12
Hookphish

Ransomware Group clop Hits: HONGHE-TECH.COM

The Clop ransomware operation has repeatedly targeted enterprise networks with intrusions that begin with phishing or exploitation of exposed systems, followed by manual lateral movement, credential theft, and domain-wide deployment. Reporting from ANSSI and AhnLab linked earlier campaigns to TA505, describing attacks in which operators used tools such as Cobalt Strike and Mimikatz, encrypted files with .Clop or .CIop extensions, and disrupted business operations at victims including E-Land Group, Software AG, and reportedly Indiabulls Group. Analysts also observed Clop using signed malware components, targeting Active Directory environments, stopping business-critical services before encryption, and in some cases preserving shadow copies depending on the variant. The group increasingly shifted from encryption-only attacks to double extortion and broader data-leak pressure tactics. Clop operators published stolen files on leak sites, demanded multimillion-dollar payments, contacted victims' customers directly to intensify pressure, and were tied to mass data-theft campaigns exploiting managed file transfer flaws such as CVE-2023-0669 in Fortra GoAnywhere MFT, which was linked to theft from about 130 companies. More recent victim listings attributed to Clop include organizations in the U.S., Canada, Peru, China, Taiwan, and Europe across technology, manufacturing, retail, and other sectors, underscoring the group's continued global focus on enterprise-scale ransomware and data-breach operations.

Aug 12
Hookphish

Ransomware Group clop Hits: 9ALTITUDES.COM

Aug 12
Hookphish

Ransomware Group clop Hits: WATERLANDPE.COM

Aug 12
Hookphish

Ransomware Group clop Hits: NETPOWER.COM

Aug 12
Hookphish

Ransomware Group clop Hits: ALDOGROUP.COM (ALDOSHOES.COM)

Aug 12
Hookphish

Ransomware Group clop Hits: IRCO.COM

Aug 12
Hookphish

Ransomware Group clop Hits: LARGAN.COM.TW

Apr 19
Bleeping Computer

March 2023 broke ransomware attack records with 459 incidents

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.