Ransomware
StormousSTMXSTMX_GhostLocker (with GhostSec)Five Families (collective member)
Attribution
Financially motivated with hacktivist ties (unattributed)
Origin
Unknown (Arabic-speaking / pro-Russia self-presentation)
Motivation
Financially motivated (ransomware)
Attribution confidence
medium
MENA targeting
Egypt, Saudi Arabia, Lebanon, Israel, Qatar, Turkey, UAE
Sectors
Education, telecom, oil & gas, government
Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Why it mattersRansomware actor, medium confidence, documented targeting Egypt, Saudi Arabia, Lebanon (Education, telecom, oil & gas sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.
No open hunts or recent alerts tracked against this actor right now.