Ransomware family
Storm Ransomware Decryption & Data Recovery
- Active
- High
- No public decryptor
Storm is a ransomware brand that surfaced in August 2026, running a Tor leak site called Storm Blog. It named around 50 organisations in roughly five weeks - mostly manufacturing, healthcare and financial services, predominantly in the United States with cases in Canada, Australia and Germany - leaning on stolen-data pressure. Public technical material is scarce and no decryptor exists.
- First seen
- 2026-08
- File extensions
- No public information
- Ransom notes
- No public information
- Affected platforms
- Windows
Public information on this family is limited. What follows is compiled from the small amount of verified material available, so please contact us for a sample assessment before you act on it.
Family profile
- File extensions
- No public information
- Ransom notes
- No public information
- Contact patterns
- Tox messenger ID (published on the negotiation entry and victim posts)
- Tor (.onion) leak site branded Storm Blog
- Dark-web negotiation page; no fixed mailbox domain seen in public material
- Aliases / versions
- Storm Blog、Storm Ransomware Group、Storm 勒索组织
- First seen
- 2026-08
- Status
- Active
- Operational status
- Newly emerged
- Threat level
- High
- Affected platforms
- Windows
- Tags
- Emerging
- Active
- Ransomware-as-a-Service
- Double extortion
No free public decryptor exists for Storm. The brand is not listed by No More Ransom, by any vendor tool set, or by law enforcement.
It is worth being precise about why: as of September 2026 no mainstream vendor has published sample-level analysis of an encryptor attributable to Storm. What is publicly visible is the leak-site posting record. The question "can Storm-encrypted files be decrypted" therefore cannot be answered at the sample level today - there is neither a usable tool nor public evidence of which cryptographic implementation is in use.
Any third party claiming a universal Storm decryptor should be treated as high risk; the usual pattern is paying the ransom on the client's behalf and reselling it at a markup.
If your files are genuinely encrypted alongside a Storm extortion threat, the correct first move is sample identification - confirming the brand and whether the encryptor is a rebadged build of a known family - and deriving the recovery path from that, rather than hunting for a decryptor first.
Latest activity
As of 9 September 2026 Storm's leak site had listed just over 50 organisations, around 40 of them within the preceding 30 days, concentrated in US, Canadian and Australian manufacturing, healthcare and finance.
SourcesStorm listed Star Aviation, a US aircraft wire-harness repair firm supplying Boeing and Airbus. Published samples included technical drawings and apparent employee ID images - its most widely covered case so far.
SourcesTrackers first indexed Storm's Tor leak site, Storm Blog, on 7 August 2026, with the earliest victim posts dated around 3 August - marking the brand's public debut.
Sources
Overview
Public information is limited. Storm only appeared in August 2026 and no vendor has published sample-level analysis, so this page draws on leak-site monitoring (ransomware.live, RansomLook) and the WatchGuard ransomware tracker, and does not cite unverified secondary reporting.
Trackers first indexed its Tor leak site, Storm Blog, on 7 August 2026; around 50 organisations had been named by early September. Roughly two thirds of victims are in the United States, with most of the remainder in Canada, Australia and Germany and an occasional UK case. Manufacturing leads by sector, followed by healthcare and financial services, and the organisations named are largely small and mid-sized. The most recent listings recorded by trackers date from early September 2026, and the leak site's availability is intermittent.
A note on naming. This entry covers the brand behind Storm Blog - not Microsoft's Storm-XXXX designations (including Storm-1175 and its StormEncryptor payload) and not the pro-Russian crew Stormous. No public reporting links them.
How to identify it
There is no extension or note filename to match against. No encrypted-file extension or note name attributable to Storm appears in public material, so identifying the family by its suffix does not apply. Three indicators are verifiable:
- Leak-site listing. The company name and sample screenshots appear on the Storm Blog onion site - the most reliable attribution point.
- Contact channel. A Tox ID as the negotiation entry point rather than a fixed mailbox domain; trackers have recorded the IDs it publishes.
- Inventory of stolen files. Listings carry screenshots of exfiltrated files that can be compared against real internal documents. Public material is too thin to generalise about which data types the operators prefer, so do not reason backwards from that to attribution.
A frequent misidentification. If the files on site carry the .encrypted extension and the note is named !!!README_FIRST!!!.txt, that is StormEncryptor, deployed by the actor Microsoft tracks as Storm-1175, and it is unrelated to the Storm brand on this page - both the response and the intelligence you cite should follow a different track.
Impersonation between young brands is common, so the name alone is not sufficient for attribution.
Infection vectors
Storm's initial access route has no authoritative public conclusion: no vendor report documents its TTPs, so any specific vector claim is speculation.
Victimology supports only limited inference - small and mid-sized manufacturers and professional services firms dominate, which fits opportunistic bulk intrusion. Trackers classify it as a RaaS or data-broker operation with affiliates, so entry points are unlikely to be uniform.
The priority is therefore not which flaw Storm uses but closing the surface such brands rely on: internet-facing RMM consoles, and VPN or RDP without multi-factor authentication.
Encryption behavior
No public analysis of encryption behaviour exists. As of September 2026 no vendor has released an encryptor sample attributable to Storm, so algorithms, encryption pattern and recovery-inhibition behaviour are left unstated rather than guessed at.
What is confirmed is data theft and public coercion; trackers label the operation as using both direct and double extortion, implying some incidents may involve deployed encryption while others are theft-only.
So do not assume recoverable encrypted files exist, and equally do not assume they do not. Forensics must first establish whether files were encrypted, the window and volume of exfiltration, and whether a foothold remains.
One caveat on the profile table: the "Windows" entry is a minimal reasonable label based on the enterprise environments targeted, not a sample-confirmed fact. Whether a Linux or ESXi encryptor exists is equally unevidenced in public sources, so on-site assessment should rely on measurement rather than this page.
Assess before you act
Recoverability assessment
1) Free decryptor. None exists; Storm is listed by neither No More Ransom nor any vendor.
2) Structural repair, if encryption occurred. Measure coverage first. Under partial encryption, database files, virtual disks and mail stores may retain intact regions, making page-level extraction and logical rebuilds worth attempting; end-to-end encryption closes this route.
3) Backups, snapshots and shadow copies. Offline and offsite backups, storage-layer and hypervisor snapshots and backup-server copies - usually the most controllable path. Never reattach backup media to a network that may still contain a foothold.
4) Unencrypted copies and log replay. File-server recycle bins, endpoint caches, ERP archive exports and transaction logs can support reconstruction.
5) Low-level carving. Where originals were deleted, data may survive in unallocated clusters and can be recovered by sector scanning - provided writes stop immediately.
Theft-only coercion, Storm's most common shape. The focus is leak-impact assessment and containment: bound what left, identify the personal data and trade secrets involved, meet notification duties and rotate credentials estate-wide.
We do not pay ransoms and do not negotiate, and we make no unconditional promise about the outcome - what we commit to is a verifiable assessment and a clearly bounded recovery scope.
Our response plan
Hit by Storm ransomware? What to do
Containment and forensic preservation
Cut affected hosts off from the internet and from lateral paths while preserving memory and disk state. Do not reboot or power off. Image or snapshot the domain controller, file servers, engineering repositories and backup server first, and export logs from edge devices, VPN, remote management consoles and Active Directory. If encrypted files exist, keep three to five samples plus every original note; if only a threat was received, preserve the emails, Tox conversation screenshots and leak-site page captures in full.
Brand verification and kill-chain analysis
Storm lacks the usual fingerprints of an extension and note filename, so this step is about verification rather than template matching. Cross-check the leak-site record, the Tox ID and the actual inventory of exfiltrated files to confirm the brand and rule out impersonation or a broker-operated shell. Separate Microsoft's Storm-XXXX numbering and entities such as Stormous from this brand to avoid citing the wrong intelligence. Where an encryptor exists, reverse the sample to determine whether it is a rebadged known family and to measure encryption coverage and stride.
Dual assessment: recoverability and leak impact
Run two tracks in parallel. Recovery track: inventory backups, storage and hypervisor snapshots and unencrypted copies, and run sample repairs on critical databases and VMs. Leak track: reconstruct the exfiltration window and volume from egress logs and traces of cloud sync or transfer utilities, compare against samples already published on the leak site, and bound the personal data, drawings, source code and contracts involved, together with the resulting notification duties and customer disclosure scope. Deliver a written assessment and priority order before execution.
Recovery execution and leak containment
All work happens on images or copies with originals kept read-only. Restore in business priority order - identity systems, core databases, then file and mail systems - with integrity checks and business-side verification after each batch. In parallel on the leak side: rotate account passwords, API keys and certificates estate-wide, revoke suspicious sessions and tokens, run an asset impact review and any necessary changes on published drawings or source code, and complete regulator, customer and supply-chain notifications per plan.
Attribution, hardening and handover
Reconstruct the full intrusion path: whether entry came from an exposed remote management console, VPN or RDP without MFA, or reuse of stolen credentials. Remove persistence, rogue accounts, scheduled tasks and GPO backdoors. Enforce MFA on VPN and remote administration, reduce internet exposure and apply access allowlisting to RMM consoles. Separate access rights for engineering repositories and source control, and deploy egress monitoring for bulk data transfer. Rebuild backups to a 3-2-1 design with immutable copies. Close with an incident report and a formal handover checklist.
Risk warning
What not to do
- Do not treat the case as minor because nothing was encrypted - Storm's leverage is the data already taken, and the attacker frequently still holds a foothold.
- Do not reboot or rebuild affected hosts; once in-memory persistence, transfer tooling and account artefacts are lost, the exfiltration scope cannot be bounded and notification duties lose their evidentiary basis.
- Do not contact the operators over Tox to "see what they want" by following the note or leak-site instructions; unplanned contact reveals your negotiating posture and internal details, which are used to raise the price.
- Do not reattach backup media or offline copies to the network before the backdoor is confirmed removed - this is the most common trigger for re-encryption and a second round of theft.
- Do not trust third parties claiming a universal Storm decryptor or the ability to have leak pages taken down; no public decryptor exists and such offers usually amount to reselling a paid ransom at a markup.
- Do not publicly attribute the incident to Storm before sample verification; impersonation and broker-operated shells are common, and misattribution affects insurance claims and later attribution work.
Emergency response
Data already encrypted? Stop and let an engineer look first
We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.
Related scenarios
File Servers and NAS Encrypted by Ransomware
When shared folders on a file server or NAS are encrypted, drawings, contracts, archives, quotations and design sources all become unusable at once — and mapped drives spread the impact to every endpoint. This page covers how to gauge spread, what shadow copies and snapshots realistically offer, and how to sequence recovery by business value.
Domain Controller Compromise and Estate-Wide Encryption
A compromised domain controller hands the attacker a legitimate administrator identity, allowing an encryptor to be pushed to every host at once through Group Policy or remote execution. This page covers how such incidents present, the correct order for Active Directory recovery, and how to decide between cleanup and full rebuild.
ERP System Encrypted by Ransomware
An encrypted ERP is not a single broken database: the application tier, database, attachments and interfaces fail together, halting finance, procurement, production and inventory. This page covers the vulnerability entry points seen in Chinese ERP deployments, the order in which the four tiers are recovered, and how account sets are reconciled at sign-off.
Related industries
Manufacturing Ransomware Response and Recovery
Ransomware in manufacturing hits information systems and production cadence at the same time: with ERP down there are no orders, with MES down there is no schedule, and an encrypted drawing library takes the process documentation for an entire product line with it. This page covers the asset profile, recovery priorities and targeted defences.
Healthcare Ransomware Response and Recovery
When a hospital is hit, registration, consultation, orders, billing, laboratory and imaging fail at the same moment and care falls back to paper. This page covers the healthcare threat picture, a recovery priority built around clinical continuity, and the handling of patient data and compliance obligations.
Financial Services Ransomware Response and Recovery
Financial and quasi-financial institutions face far stricter requirements on data integrity, transaction continuity and regulatory reporting than most sectors, so one ransomware event hits availability, customer trust and compliance simultaneously. This page covers the threat profile, a recovery approach centred on transactional consistency, and hardening priorities.
Similar families
- No public decryptor
Settra
Settra is an extortion crew that surfaced in June 2026, negotiating over Tox and publishing long-form, expose-style victim write-ups on its Tor leak site. It has named roughly 64 organisations in three months. No encryptor sample has been publicly analysed and no decryptor exists.
- Some versions decryptable
The Gentlemen
The Gentlemen is a RaaS operation that surfaced in mid-2025 and reached the top tier of global ransomware activity in 2026. It is marked by README-GENTLEMEN.txt notes and a six-character extension (.umc16h in the publicly analysed build), ships Windows and Linux/ESXi lockers, and combines self-propagation with an in-house EDR-killing framework.
- No public decryptor
DireWolf
DireWolf (Dire Wolf) is a Go-based ransomware crew that surfaced in May 2025, marked by the .direwolf extension and a HowToRecoveryFiles.txt note. It runs double extortion from a Tor leak site, ships a Windows-only encryptor, and encrypts just the first 1 MB of files larger than 1 MB - which leaves real repair space for databases and virtual disks.
FAQ
Storm Frequently asked questions
Can files encrypted by Storm be decrypted?
There is no free public decryptor for Storm; the brand is not listed by No More Ransom or by any vendor.
More importantly, as of September 2026 no vendor has published analysis of an encryptor attributable to Storm, so even the question of which cryptographic implementation it uses has no public answer. Recoverability can therefore only be judged from your actual files: whether anything was truly encrypted, whether coverage is whole-file or partial, and whether usable backups and snapshots exist. We produce an assessment first and define recovery scope from it, rather than assuming an outcome.
Is Storm the same as Microsoft's Storm-1175 and StormEncryptor?
No - and this is the most common misreading.
Microsoft assigns temporary Storm-XXXX designations to threat clusters it has not yet fully characterised. Storm-1175 is one of them: public reporting from August 2026 describes it as a former Medusa affiliate that deployed an encryptor called StormEncryptor through a vulnerability in N-able N-central remote monitoring software, appending
.encryptedand dropping a note named!!!README_FIRST!!!.txt.The Storm on this page is a self-styled brand operating a dark-web leak site called Storm Blog, with no published extension or note filename to match against. No public reporting establishes a link between the two, and the similarly named pro-Russian crew Stormous is also unrelated to this entry.
Note that some secondary news sites have already merged these two stories into one. When citing intelligence during response, anchor on leak-site attribution and sample characteristics rather than name similarity - and if you do find
.encryptedand!!!README_FIRST!!!.txton site, handle it as StormEncryptor.Nothing was encrypted and we only got a data-leak threat. Does it still need handling?
Yes, and at no lower priority than an encryption incident.
Storm's leverage is the data already exfiltrated, and the absence of encryption does not mean the attacker has left. The opposite is more likely: completing a large-scale transfer implies a period of dwell time, and the foothold, stolen credentials and backdoors often remain usable. Three things must be done: bound the exfiltration scope and time window, remove persistence and rotate credentials across the estate, and assess notification duties under applicable law.
Skipping forensics to restore operations typically ends one of two ways - the same entry point is reused months later, or the organisation cannot describe the breach scope when a regulator asks.
How do we verify the incident really is Storm?
Storm has no published extension or note filename to match, so identifying the family by its suffix does not work here. Three indicators are verifiable and worth cross-checking:
- Leak-site listing - whether the company name and sample screenshots appear on the Storm Blog onion site.
- Contact channel shape - whether a Tox ID is the negotiation entry point rather than a fixed mailbox domain.
- Exfiltrated file inventory - whether the samples shown map one-to-one onto real internal files, and whether they let you infer the transfer window.
Impersonation between young brands and broker-operated listings were common through 2026, so the word Storm in a note is not sufficient. Misattribution affects insurance claims, the wording of regulatory notifications, and the direction of later attribution work.
They set a deadline. Should we open negotiations to buy time?
We do not pay ransoms, do not negotiate on a client's behalf, and do not advise making contact without a plan and legal counsel.
Technically, reaching out does not change the fact that data has already left. It does reveal how sensitive you consider the data, your internal decision tempo and your tolerance - all of which are used to raise the price and the pressure. Effort is better spent on what you control: forensics to bound the exfiltration scope, removing persistence to prevent a second incident, meeting notification duties, and running an asset impact review with any necessary changes on drawings or source code already published.
Where cross-border operations or listed-company disclosure duties are involved, bring legal and compliance in at the same time and let them own external messaging.
Sources
- WatchGuard Ransomware Tracker — Storm
- Ransomware.live — Storm group profile
- RansomLook — Storm
- BleepingComputer — New StormEncryptor ransomware used by former Medusa affiliate(用于区分 Storm-1175 / StormEncryptor)
- No More Ransom — 解密工具列表(未收录 Storm)
External links are provided for reference only. The content is published by third parties and does not represent our position.
Updated