Active ransomware operator
← All groupsStorm
9 victims indexed · first seen 1 day ago · last activity 3 hours ago
At a glance
- Status
- active
- First seen
- 1 day ago
- Last activity
- 3 hours ago
- Primary sector
- Healthcare · 3 hits
About
Timeline
1 monthsTop countries
Top sectors
MITRE ATT&CK
68 techniques · 14 tacticsTactics
Techniques
- T1003.001LSASS Memory
- T1003.004LSA Secrets
- T1003.005Cached Domain Credentials
- T1016System Network Configuration Discovery
- T1027.003Steganography
- T1027.004Compile After Delivery
- T1027.010Command Obfuscation
- T1033System Owner/User Discovery
- T1036.005Match Legitimate Resource Name or Location
- T1041Exfiltration Over C2 Channel
- T1047Windows Management Instrumentation
- T1049System Network Connections Discovery
- T1053.005Scheduled Task
- T1057Process Discovery
- T1059.001PowerShell
- T1059.003Windows Command Shell
- T1059.005Visual Basic
- T1059.006Python
- T1059.007JavaScript
- T1071.001Web Protocols
- T1074.001Local Data Staging
- T1082System Information Discovery
- T1083File and Directory Discovery
- T1087.002Domain Account
- T1090Proxy
- T1090.002External Proxy
- T1102.002Bidirectional Communication
- T1104Multi-Stage Channels
- T1105Ingress Tool Transfer
- T1113Screen Capture
- T1132.001Standard Encoding
- T1137.001Office Template Macros
- T1140Deobfuscate/Decode Files or Information
- T1190Exploit Public-Facing Application
- T1203Exploitation for Client Execution
- T1204.001Malicious Link
- T1204.002Malicious File
- T1204.004Malicious Copy and Paste
- T1210Exploitation of Remote Services
- T1218.003CMSTP
- T1218.005Mshta
- T1218.011Rundll32
- T1219.002Remote Desktop Software
- T1518Software Discovery
- T1518.001Security Software Discovery
- T1534Internal Spearphishing
- T1547.001Registry Run Keys / Startup Folder
- T1548.002Bypass User Account Control
- T1552.001Credentials In Files
- T1555Credentials from Password Stores
- T1555.003Credentials from Web Browsers
- T1559.001Component Object Model
- T1559.002Dynamic Data Exchange
- T1560.001Archive via Utility
- T1566Phishing
- T1566.001Spearphishing Attachment
- T1566.002Spearphishing Link
- T1567.002Exfiltration to Cloud Storage
- T1571Non-Standard Port
- T1573.001Symmetric Cryptography
- T1574.001DLL
- T1583.001Domains
- T1583.006Web Services
- T1588.001Malware
- T1588.002Tool
- T1590.004Network Topology
- T1684.001Impersonation
- T1685Disable or Modify Tools
Recent victims
Loading…
Source
Updated 3 hours agoData on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.
Get alerted the next time Storm posts a victim.
Add Storm to your watchlist — Pro pings you within 5 minutes of any new Storm leak-site post, Telegram callout, or affiliate-rebrand inference.

