◇ SIGN IN
← all actors
ransomware

Stormous

activemedium confidence
Ransomware
StormousSTMXSTMX_GhostLocker (with GhostSec)Five Families (collective member)
Attribution
Financially motivated with hacktivist ties (unattributed)
Origin
Unknown (Arabic-speaking / pro-Russia self-presentation)
First seen
2021
Last active
2025
Motivation
Financially motivated (ransomware)
Confidence
medium
MENA targeting
Egypt, Saudi Arabia, Lebanon, Israel, Qatar, Turkey, UAE
Sectors
Education, telecom, oil & gas, government

Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.

Why it mattersRansomware actor, medium confidence, documented targeting Egypt, Saudi Arabia, Lebanon (Education, telecom, oil & gas sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

Stormous is a ransomware and extortion group with hacktivist framing, a member of the 'Five Families' collective, that ran joint ransomware-as-a-service operations with GhostSec and has repeatedly claimed victims across the Middle East.

History

Stormous appeared around 2021-2022, presenting a pro-Russia, hacktivist-flavored brand while conducting financially motivated extortion. It is a member of the self-styled 'Five Families' collective (alongside GhostSec, ThreatSec, SiegedSec and Blackforums). In February 2024 Stormous and GhostSec announced a joint RaaS program, 'STMX_GhostLocker', and in May 2024 GhostSec reportedly handed GhostLocker to Stormous while returning to hacktivism; Stormous continued operating the RaaS into 2025.

Talos and others documented joint GhostSec/Stormous ransomware operations spanning more than 15 countries, including a claimed attack on an Egyptian private healthcare firm using GhostLocker to encrypt EMR systems with claims of over 250,000 patient files.

Stormous has claimed victims across Egypt, Saudi Arabia, Lebanon, Israel, Qatar, Turkey and the UAE. Given the group's hacktivist framing and history of exaggeration, these leak-site and Telegram claims should be treated as unverified allegations rather than confirmed breaches unless independently corroborated.

Notable campaigns

2024
STMX_GhostLocker joint RaaS
Stormous and GhostSec launched a joint ransomware-as-a-service program announced via the Five Families channel.
2024
Egyptian healthcare claim
A private Egyptian healthcare firm was claimed as a GhostLocker victim with alleged theft of 250,000+ patient files (claimed).
2024
Multi-country MENA claims
Joint operations were claimed across Egypt, Lebanon, Israel, Qatar, Turkey and other states (claimed, not confirmed).

Claimed victims · 188 tracked

Leak-site postings via ransomware.live — claimed by the group, not confirmed breaches. Metadata only. MENA Ransomware Watch →

Claim volume · last 12 months
SONDJFMAMJJA
DateVictimCountrySector
higuchi-inc.co.jpJPManufacturing
HIGUCHI USA, INCUSManufacturing
eogb.co.ukGBEnergy & Utilities
eshacloudqa.comUSTechnology
monoprix.tnTunisiaRetail & E-Commerce
Official Statement: Protecting palatineschool.org InfrastructureEducation
maglificioliliana.com
lorenzoni-store.comITRetail & E-Commerce
montechiaro-store.comITRetail & E-Commerce
impulso-store.comMXRetail & E-Commerce
jaggroup.com UPDATE-FULL DATA DUMP
mlit.com.myMYGovernment & Defense