Stormous is an Arabic-speaking, pro-Russian ransomware group active since 2022 targeting government and energy sectors.
Analyst brief
Stormous is an Arabic-speaking, pro-Russian ransomware and hacktivist group active since 2022. It targets government, defense, energy, technology, retail, and manufacturing sectors primarily in the United States, Italy, Japan, the United Kingdom, and other countries. The group collaborates with GhostSec on the GhostLocker 2.0 RaaS platform and took over GhostSec's RaaS operations in mid-2024 (announced cessation of operations on July 1, 2026). Defenders should prioritize regular backup verification, enforce multi-factor authentication (MFA), and strengthen network monitoring for IoCs linked to politically motivated RaaS threats.
stormous
activecrime
Stormous is an Arabic-speaking, pro-Russian ransomware and hacktivist group active since at least 2022, known for politically motivated attacks across 15+ countries, collaborating with GhostSec on the GhostLocker 2.0 RaaS platform and inheriting GhostSec's RaaS operations in mid-2024.
On 1st July 2026 the group has annonced the end of their operations & ervices