Stormous is a PHP-based malware family associated with the Stormous ransomware operation. It has been described as unusual among ransomware tooling because it combines backdoor functionality with file-encryption and ransom-note deployment, allowing operators to obtain remote access to compromised servers and then deliver additional custom payloads. Reported capabilities include malware dropping, remote access for follow-on activity, and ransomware execution.
Stormous has been publicly aligned with pro-Russian messaging during the Russia-Ukraine conflict and declared intent to target Ukrainian government institutions. Analysis has linked the operation to Arabic-speaking actors, likely from North Africa. The malware has been characterized as rapidly modifiable, reflecting its PHP implementation and use against web-facing environments.
Targeting has focused on web servers and vulnerable web applications running PHP. Stormous is primarily known as part of a ransomware and extortion operation rather than a commodity malware family, and it has appeared in multiple ransomware activity rankings and leak-site tracking during 2023 and 2025. The group has also operated a data leak site and, in some periods, relied on Telegram for victim disclosures and extortion-related publicity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Stormous is one of the few exceptions. Aside from being a backdoor, it also contains ransomware functionality.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operation referenced as minimal activity in Q2 2025 (no additional detail provided).
Ransomware group known for targeting hotels, resorts, and claiming attacks on large companies, though some claims are unsubstantiated.
Ransomware family mentioned as having relatively significant activity during March 2023.
リークサイトや Telegram を中心に活動し、新たなリークサイトが 2023年3月に発見されたランサムウェア攻撃グループとして統計内で言及されている。本文では、実際にランサムウェアを使用するか疑義もあるが、検体発見などから集計対象に含めていると説明されている。
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.