Ransomware Group intelligence
Storm
ActiveTrack Storm with 105 published victims and 1 known leak locations in a single intelligence view.
Overview
Storm is tracked by Breach House as a ransomware group with 105 published victims.
United States is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Leak Status Distribution
- Leaked 24 37.5%
- Pending 40 62.5%
- Deleted 0 0.0%
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Up checked 13h ago | yqhecvqtdvq6p7duqcgw2qca77spbgakxcoibtx6zpvfshltsbbbhfqd.onion |
Top Activity Sectors (13)
Typical Attacks (9)
▼MITRE ATT&CK does not currently catalogue Storm, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: Storm executes malicious payloads through PowerShell scripts to stage ransomware components across victim systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1569.002 Service Execution Execution
What they do: Storm executes ransomware binaries through Windows Service installation to ensure persistence.
What that means: Adversaries may abuse the Windows service control manager to execute malicious commands or payloads.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Storm disables security tools by terminating antivirus processes and modifying Windows Defender service configurations.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: Storm deletes Volume Shadow Copy snapshots via vssadmin and NTFS metadata to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1083 File and Directory Discovery Discovery
What they do: Storm uses file and directory discovery via PowerShell to enumerate critical data paths before encryption.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: Storm leverages SMB/Windows Admin Shares for lateral movement across networked servers in Finance and IT environments.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: Storm encrypts victim files using custom symmetric encryption routines targeting documents, databases, and backups.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: Storm inhibits system recovery by corrupting restore points and disabling backup service processes.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1491.001 Internal Defacement Impact
What they do: Storm performs internal defacement by replacing victim websites with ransom notices and contact pages.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
Victims (105)
Search, filter and paginate the victim timeline for Storm. Showing 101–105 of 105.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | Liberty Healthcare Corporation id31401 View details | United States | Healthcare / Pharma | leaked | ||
|
Liberty Healthcare Corporation is a prominent health and human services management company that has been addressing complex healthcare challenges for over 30 years. They specialize in health workforce outsourcing, program management, and population health management, focusing on supporting specialized and vulnerable populations. Their innovative, person-centered solutions aim to improve quality and performance in healthcare organizations. With expertise in behavioral health, aging, and intellectual developmental disabilities, Liberty Healthcare is dedicated to transforming challenges into opportunities for success. The company headquarters is located in 401 East City Avenue, Suite 820, Bala Cynwyd, PA 19004, United States. |
||||||
| Ransomware | EvansPetree id31402 View details | United States | Finance / Legal / Insurance | pending | ||
|
Evans Petree is a company based in the United States, operating within the finance, legal, and insurance sector. The firm provides various services to its clients. Evans Petree was listed as a ransomware victim associated with Storm. |
||||||
| Ransomware | EvansPetree id31402 View details | United States | Finance / Legal / Insurance | pending | ||
|
Evans Petree has maintained a strong and effective dispute resolution/litigation practice for over 100 years. The company's dispute resolution/litigation attorneys are skilled at negotiation, mediation, arbitration and other dispute resolution mechanisms in hopes of resolving your disputes and issues quickly and economically. "Preventive maintenance" and early discussion about resolution can often lead to the success of your objectives. If litigation becomes unavoidable, Evans Petree can handle the most complex cases at all levels of the court systems, from administrative matters to federal and state court trials and appeals. The company's objective is to provide you with aggressive, value-conscious representation and work together to successfully advocate your position. The company headquarters is located in 1715 Aaron Brenner Drive, Suite 800, Memphis, TN 38120, United States. 51-200 Employees |
||||||
| Ransomware | OVP Health id31403 View details | United States | Healthcare / Pharma | leaked | ||
|
Ovphealth.com is a healthcare organization based in the United States, operating in the medicine sector. The company provides various healthcare services to its patients. Ovphealth.com was listed as a ransomware victim associated with Storm |
||||||
| Ransomware | OVP Health id31403 View details | United States | Healthcare / Pharma | leaked | ||
|
OVP Health is a physician-owned company with over 20 years of experience in healthcare, specializing in emergency department and hospitalist staffing and management. The company offers a wide range of services including addiction treatment, behavioral health care, primary care, and telemedicine across West Virginia, Kentucky, Ohio, and Virginia. OVP Health is dedicated to addressing the needs of patients suffering from severe drug and alcohol addiction, providing both inpatient and outpatient care. Their facilities are CARF-accredited, ensuring high-quality treatment and support for individuals and families in crisis |
||||||