Storm
- First seen
- 2023-07-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Last IoC activity
- 2026-04-21 11:38:22
- Profile updated
- 2026-07-07 16:17:01
Targeted industries: healthcare-and-pharmaceutical financial-services education-and-nonprofits energy-and-utilities
Context
Storm is a ransomware strain that encrypts files on infected systems, demanding ransom payments for decryption keys. It primarily targets industries such as healthcare, financial services, and education.
Detection coverage
- 2 YARA rules
Used by threat actors
- ArcaneDoor (campaign)
- ArcaneDoor (Deprecated) (campaign)
- Operation Dust Storm (campaign)
- Storm-0501 Hybrid Cloud Compromise (campaign)
- Storm-0558 Unauthorized Email Access Activity (campaign)
- UNC2190 2021 Ransomware Activity (campaign)
Detection rules
- SEKOIA_Storm_1811_Files_Dat (yara-rule)
- SIGNATURE_BASE_MAL_RANSOM_Gentlemen_Jun26_1 (yara-rule)