Stormous is one of the few exceptions. Aside from being a backdoor, it also contains ransomware functionality.
Stormous
Stormous is a PHP-based malware family associated with the Stormous ransomware operation.
Profile source: Mallory opens in a new tabStormous
Family profile
Stormous is a PHP-based malware family associated with the Stormous ransomware operation. It has been described as unusual among ransomware tooling because it combines backdoor functionality with file-encryption and ransom-note deployment, allowing operators to obtain remote access to compromised servers and then deliver additional custom payloads. Reported capabilities include malware dropping, remote access for follow-on activity, and ransomware execution.
Stormous has been publicly aligned with pro-Russian messaging during the Russia-Ukraine conflict and declared intent to target Ukrainian government institutions. Analysis has linked the operation to Arabic-speaking actors, likely from North Africa. The malware has been characterized as rapidly modifiable, reflecting its PHP implementation and use against web-facing environments.
Targeting has focused on web servers and vulnerable web applications running PHP. Stormous is primarily known as part of a ransomware and extortion operation rather than a commodity malware family, and it has appeared in multiple ransomware activity rankings and leak-site tracking during 2023 and 2025. The group has also operated a data leak site and, in some periods, relied on Telegram for victim disclosures and extortion-related publicity.
Capabilities
- Exfiltration
- Post Exploitation
Operational record
Reported operators
Threat actors
1 named in public reportingMITRE ATT&CK
Stormous in ATT&CK
35 distinct techniquesTechniques
35 techniquesReporting
Research mentioning Stormous
Ransomware Group clop Hits: HONGHE-TECH.COM
The Clop ransomware operation has repeatedly targeted enterprise networks with intrusions that begin with phishing or exploitation of exposed systems, followed by manual lateral movement, credential theft, and domain-wide deployment. Reporting from ANSSI and AhnLab linked earlier campaigns to TA505, describing attacks in which operators used tools such as Cobalt Strike and Mimikatz, encrypted files with .Clop or .CIop extensions, and disrupted business operations at victims including E-Land Group, Software AG, and reportedly Indiabulls Group. Analysts also observed Clop using signed malware components, targeting Active Directory environments, stopping business-critical services before encryption, and in some cases preserving shadow copies depending on the variant. The group increasingly shifted from encryption-only attacks to double extortion and broader data-leak pressure tactics. Clop operators published stolen files on leak sites, demanded multimillion-dollar payments, contacted victims' customers directly to intensify pressure, and were tied to mass data-theft campaigns exploiting managed file transfer flaws such as CVE-2023-0669 in Fortra GoAnywhere MFT, which was linked to theft from about 130 companies. More recent victim listings attributed to Clop include organizations in the U.S., Canada, Peru, China, Taiwan, and Europe across technology, manufacturing, retail, and other sectors, underscoring the group's continued global focus on enterprise-scale ransomware and data-breach operations.