Classification: TLP:CLEAR | Publication Date: 2026-10-01 | Source: ransomware.live leak-site monitoring (6 listings multi-source; 1 single-source — see Sourcing & Verification) | Nature of data: Unverified threat-actor claims
STORM Ransomware Gang: 7 US Organizations Listed on Leak Site
Executive Summary
STORM's dark web leak site was observed listing seven US organizations across Healthcare, Agriculture and Food Production, Professional Services, Hospitality, Financial Services, and an uncategorized Other sector. Six listings were published on 2026-09-30 and independently observed by a second crawler; one listing, Poca Valley Bank, was published 2026-09-28 and appears only on ransomware.live.
This briefing treats every named organization as an unverified claim by a criminal actor, not as a confirmed breach. The operational signal is still useful: the posting pattern shows a short burst of US-centric naming, with sector diversity consistent with opportunistic access brokered or obtained through exposed edge services, phishing, and remote access abuse. Security teams in the named sectors should prioritize edge CVE remediation, identity telemetry review, and pre-encryption staging detection rather than waiting for encryption artifacts.
Sourcing & Verification
- Corroboration status: 6 of 7 listings were independently observed by a second leak-site crawler; 1 listing appears on a single source only.
- Inclusion in this briefing reflects the threat actor's claim and is NOT confirmation of a breach, compromise, data theft, or active incident at any named organization.
- A named organization may dispute a listing, and a denial is likewise not proof the claim is false; disclosure obligations vary by jurisdiction, sector, contract, and regulator, and not every incident is reportable, so neither silence nor denial settles the question.
- Security Arsenal will publish corrections and welcomes contact from any named organization at security@securityarsenal.com.
Threat Actor Profile — STORM
- Known aliases: No reliably corroborated aliases are present in the current collection. Treat lookalike storm-themed branding, reposts, and forum chatter as low-confidence until tied to the same onion infrastructure, PGP keys, wallet clusters, or negotiation handles.
- Operating model: Assessment is a closed or tightly controlled affiliate model rather than a fully open RaaS. The basis is the narrow US concentration, clustered posting cadence, and absence of broad multi-geography victim scatter in this 100-posting window. This is an analytic assessment, not attribution fact.
- Ransom behavior: The observed listings do not publish consistent demand amounts. For planning, assume demands are scaled to perceived revenue, insurance posture, and regulatory sensitivity, with double extortion used to pressure payment even where encryption is partial or disrupted.
- Initial access methods: Consistent with the broader ransomware ecosystem and the exposure themes below, likely vectors include phishing with macro or script payloads, exploitation of internet-facing VPN/firewall/remote management services, weak or reused RDP credentials, and supply-chain or developer-tool compromise where those paths are exposed. No named organization in this briefing is tied to a specific vector.
- Double extortion: The presence of leak-site naming indicates an extortion-first workflow: claim, threaten publication, then escalate with sample data, countdowns, or partial dumps. Defenders should assume data staging may occur before any encryption event.
- Dwell time: Not directly measurable from leak-site data. Use a planning assumption of days to weeks for hands-on-keyboard intrusion paths, but treat edge-CVE exploitation as potentially hours-to-days from access to extortion if the actor buys working access.
Current Campaign Analysis
Organizations listed
STORM has listed, named, or claims to have compromised the following organizations; these remain unverified threat-actor claims:
- West County Health Centers — Healthcare, US — published 2026-09-30 — MULTI-SOURCE claim observed.
- Gardeners' Guild — Agriculture and Food Production, US — published 2026-09-30 — MULTI-SOURCE claim observed.
- North Hills Facility Services — Professional Services, US — published 2026-09-30 — MULTI-SOURCE claim observed.
- Olnick Rentals — Hospitality, US — published 2026-09-30 — MULTI-SOURCE claim observed.
- Silvercup Studios — Other, US — published 2026-09-30 — MULTI-SOURCE claim observed.
- Century Management Services — Professional Services, US — published 2026-09-30 — MULTI-SOURCE claim observed.
- Poca Valley Bank — Financial Services, US — published 2026-09-28 — SINGLE-SOURCE claim only.
Sector targeting
The current set spans regulated and operationally sensitive sectors: healthcare, banking/financial services, food production, facilities/professional services, hospitality, and media/studio operations under Other. This is consistent with extortion leverage rather than a single vertical exploit chain: pressure is created through downtime risk, confidentiality obligations, customer trust, and contractual disruption.
Geographic concentration
All listed organizations are in the US. That concentration can reflect victim access availability, affiliate preference, insurance and payment expectations, language and negotiation capability, or deliberate targeting of US disclosure pressure. It should not be read as proof that only US entities are exposed.
Victim profile
Based on sector composition only, the listed set appears weighted toward small-to-midsize enterprises and midmarket organizations rather than global Fortune-scale brands. Healthcare clinics, regional banks, food and agricultural operators, facilities services, rental/hospitality operators, and studio/production businesses often run lean IT teams, hybrid identity, outsourced MSP support, and legacy remote access. Revenue estimates are not provided by the leak data; defenders should model impact using business interruption, regulatory exposure, and data sensitivity rather than assuming a demand figure.
Posting frequency and escalation pattern
The pattern is a burst: six claims on 2026-09-30 plus one earlier single-source claim on 2026-09-28. A same-day multi-listing burst can indicate batch publishing after a collection period, affiliate handoff, or an attempt to maximize attention. Watch for countdown timers, sample-data posts, reposts to mirrors, and translation into Telegram or breach forums as escalation indicators.
CVE exposure hypothesis
No evidence links any named organization to a specific CVE, and this briefing does not assert an initial access vector for any listed entity. At sector level, STORM defenders should prioritize confirmed actively exploited edge and management-plane issues from CISA KEV: CVE-2026-59310 VMware vCenter path traversal, CVE-2026-63077 JetBrains TeamCity deserialization, CVE-2026-20316 Cisco Secure FMC hard-coded password, CVE-2026-50751 Check Point Security Gateway improper authentication, and CVE-2026-48027 Nx Console embedded malicious code. These map to common ransomware entry themes: virtualization control plane, CI/CD supply chain, firewall management, VPN gateway authentication, and developer endpoint tooling.
Detection Engineering
---
title: STORM Suspected Pre-Ransomware Staging and Defense Evasion
id: 8f0f6f25-4a19-4b93-9e5a-2a7f0a11a001
status: experimental
description: Detects common pre-encryption staging and defense evasion patterns associated with ransomware intrusions, including shadow copy deletion, backup tampering, and mass file discovery before extortion.
references:
- https://securityarsenal.com/darkside
author: Security Arsenal
date: 2026/10/01
logsource:
product: windows
category: process_creation
level: high
detection:
selection_cmd:
CommandLine|contains:
- 'vssadmin delete shadows'
- 'vssadmin resize shadowstorage'
- 'wbadmin delete catalog'
- 'bcdedit /set'
- 'recoveryenabled no'
- 'ignoreallfailures'
selection_ransom_note:
CommandLine|contains:
- 'readme_for_unlock'
- 'restore_files'
- 'how_to_decrypt'
- 'recover_instructions'
condition: selection_cmd or selection_ransom_note
falsepositives:
- Legitimate backup administration, imaging, or system recovery work performed by IT during change windows
---
title: STORM Remote Access and Lateral Movement Tool Execution
id: 8f0f6f25-4a19-4b93-9e5a-2a7f0a11a002
status: experimental
description: Detects PsExec-style service execution, WMI remote process creation, Cobalt Strike-like rundll32 patterns, and suspicious use of remote administration tooling from non-admin hosts.
references:
- https://securityarsenal.com/darkside
author: Security Arsenal
date: 2026/10/01
logsource:
product: windows
category: process_creation
level: high
detection:
selection_psexec:
Image|contains:
- '*psexec*'
- '*psexesvc*'
- '*paexec*'
- '*remcomsvc*'
selection_wmi:
ParentImage|contains: '*wmiprvse.exe'
Image|contains:
- '*powershell.exe'
- '*cmd.exe'
- '*rundll32.exe'
- '*regsvr32.exe'
selection_beacon:
CommandLine|contains:
- 'rundll32.exe'
- 'StartW'
- 'DllRegisterServer'
- 'javascript:'
- 'mshtml,RunHTMLApplication'
condition: selection_psexec or (selection_wmi and selection_beacon)
falsepositives:
- Enterprise software distribution, SCCM, Intune, administrative remote support, and signed management agents
---
title: STORM Edge Exposure and Password Spray Follow-on Activity
id: 8f0f6f25-4a19-4b93-9e5a-2a7f0a11a003
status: experimental
description: Detects authentication bursts consistent with VPN/RDP brute force, password spraying, or valid-account misuse followed by privileged tool execution.
references:
- https://securityarsenal.com/darkside
author: Security Arsenal
date: 2026/10/01
logsource:
product: windows
service: security
level: medium
detection:
selection_failed:
EventID: 4625
selection_success:
EventID: 4624
LogonType:
- 3
- 7
- 10
timeframe: 10m
condition: selection_failed | count() > 20 by IpAddress, TargetUserName
falsepositives:
- Misconfigured service accounts, VPN MFA retries, legacy scanners, and load-balanced authentication probes
let lookback = 7d;
let staging_terms = dynamic(['vssadmin','wbadmin','bcdedit','psexec','psexesvc','wmiprvse','rundll32','regsvr32','7z','rar','winscp','megacmd','rclone','restic']);
let edge_terms = dynamic(['vpn','rdp','anyconnect','globalprotect','forticlient','check point','fmc','teamcity','vcentervpxd','nx console']);
union
( DeviceProcessEvents
| where TimeGenerated >= ago(lookback)
| where ProcessCommandLine has_any (staging_terms) or InitiatingProcessCommandLine has_any (staging_terms)
| project TimeGenerated, DeviceName, AccountName, ProcessCommandLine, InitiatingProcessCommandLine, FileName, SHA256, ReportId
),
( DeviceLogonEvents
| where TimeGenerated >= ago(lookback)
| where RemoteIP has_any ('.') and LogonType in ('Interactive','RemoteInteractive','Network')
| summarize FailedLike=countif(ActionType=='LogonFailed'), SuccessLike=countif(ActionType=='LogonSuccess'), DistinctAccounts=dcount(AccountName) by RemoteIP, DeviceName, bin(TimeGenerated, 10m)
| where FailedLike >= 15 or (SuccessLike >= 1 and DistinctAccounts >= 5)
| project TimeGenerated, DeviceName, RemoteIP, FailedLike, SuccessLike, DistinctAccounts
),
( DeviceNetworkEvents
| where TimeGenerated >= ago(lookback)
| where RemoteUrl has_any (edge_terms) or InitiatingProcessCommandLine has_any (edge_terms)
| project TimeGenerated, DeviceName, RemoteUrl, RemoteIP, RemotePort, InitiatingProcessCommandLine, ActionType
)
| order by TimeGenerated desc
# Rapid STORM-oriented exposure and staging check. Run elevated on suspect servers and jump hosts.
$since = (Get-Date).AddDays(-7)
Write-Host '[1] RDP exposure'
$rdp = Get-ItemProperty -Path 'HKLM:/System/CurrentControlSet/Control/Terminal Server' -Name fDenyTSConnections -ErrorAction SilentlyContinue
if ($rdp -and $rdp.fDenyTSConnections -eq 0) { Write-Host 'RDP appears ENABLED. Restrict by firewall/VPN, require NLA and MFA.' }
Get-NetTCPConnection -State Listen -ErrorAction SilentlyContinue | Where-Object { $_.LocalPort -in 3389,5985,5986 } | Select-Object LocalAddress,LocalPort,OwningProcess
Write-Host '[2] Scheduled tasks created or changed in last 7 days'
Get-ScheduledTask | ForEach-Object { try { $i = Get-ScheduledTaskInfo -TaskName $_.TaskName -TaskPath $_.TaskPath -ErrorAction Stop; [pscustomobject]@{Task=$_.TaskPath+$_.TaskName; Author=$_.Author; LastRun=$i.LastRunTime; NextRun=$i.NextRunTime} } catch {} } | Sort-Object Task
Write-Host '[3] Suspicious process and security events in last 7 days'
Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4624,4625,4672,4728,4732,4756; StartTime=$since} -MaxEvents 200 -ErrorAction SilentlyContinue | Select-Object TimeCreated,Id,Message
Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Sysmon/Operational'; Id=1,3,7,8,10,11; StartTime=$since} -MaxEvents 300 -ErrorAction SilentlyContinue | Where-Object { $_.Message -match 'vssadmin|wbadmin|bcdedit|psexec|rclone|7z|megacmd|rundll32|regsvr32' } | Select-Object TimeCreated,Id,Message
Write-Host '[4] Volume Shadow Copy posture'
Get-CimInstance Win32_ShadowCopy -ErrorAction SilentlyContinue | Select-Object ID,InstallDate,DeviceObject,VolumeName
vssadmin list shadows
Write-Host '[5] Large archive and exfil tools in common write paths'
$paths = @('C:/Users','C:/ProgramData','C:/Windows/Temp')
foreach ($p in $paths) { if (Test-Path $p) { Get-ChildItem $p -Recurse -Force -ErrorAction SilentlyContinue | Where-Object { $_.LastWriteTime -gt $since -and ($_.Extension -in '.zip','.7z','.rar','.tar','.gz','.bak' -or $_.Name -match 'rclone|winscp|megacmd|restic') } | Select-Object FullName,Length,LastWriteTime } }
Incident Response Priorities
T-minus detection checklist: before encryption fires
- Edge authentication: sudden failed logon bursts against VPN, firewall admin portals, RDP, OWA, or remote management; impossible travel; new MFA device enrollment; disabled MFA prompts; logons at unusual hours.
- Management-plane anomalies: vCenter, firewall manager, EDR console, backup console, and CI/CD logins from new hosts or service accounts.
- Staging behavior: creation of large archives, 7z/rar/rclone/restic/megacmd execution, unusual SMB writes to a single collection host, and temporary folders under ProgramData or user profile roots.
- Defense evasion: vssadmin or wbadmin deletion, bcdedit recovery changes, EDR service stops, event log clearing, new local admins, and Group Policy changes that weaken controls.
- Lateral movement: PsExec-like services, WMI child processes, remote scheduled tasks, unexpected 7045 service installs, and admin share access from workstations to servers.
Critical assets historically prioritized for exfiltration
For STORM-like double-extortion operations, assume priority on domain controllers, backup servers, file shares with HR/legal/finance data, EHR or patient-adjacent repositories in healthcare, core banking or customer records in financial services, contracts and payroll in professional services, reservation and guest data in hospitality, and unreleased media or production assets in studio environments. Treat this as sector-risk prioritization, not evidence of access at any named organization.
Containment actions ordered by urgency
- Isolate suspected staging hosts and any system showing shadow-copy deletion, mass archive creation, or unauthorized admin-tool execution; preserve memory and triage images before shutdown where feasible.
- Disable or rotate credentials tied to abnormal logons, especially VPN, firewall, vCenter, backup, EDR, service accounts, and domain admins; revoke tokens and sessions.
- Block egress for known exfil tools and unsanctioned cloud storage while preserving business-critical backup replication; inspect proxy, DNS, and TLS SNI telemetry.
- Protect backups: verify immutability, isolate backup networks, rotate backup credentials, and test one restore path before declaring recoverability.
- Snapshot edge systems and management planes before patching if compromise is suspected; capture logs from VPN, firewall, vCenter, TeamCity, FMC, Check Point, and identity providers.
- If any named organization contacts Security Arsenal or disputes a claim, route through legal and communications while preserving forensic evidence and avoiding public confirmation either way.
Hardening Recommendations
Immediate — 24 hours
- Patch or mitigate CISA KEV items where present: CVE-2026-59310 vCenter, CVE-2026-63077 TeamCity, CVE-2026-20316 Cisco Secure FMC, CVE-2026-50751 Check Point Security Gateway, and CVE-2026-48027 Nx Console. If patching cannot complete immediately, remove internet exposure, restrict to allowlists, and add virtual patching/WAF or VPN ACL controls.
- Enforce phishing-resistant MFA for VPN, firewall admin, remote management, cloud identity, email, and privileged consoles; disable legacy authentication.
- Restrict RDP and WinRM to jump hosts; deny inbound 3389/5985/5986 from the internet; require NLA; alert on new RDP listeners.
- Enable and forward logs for Windows Security, Sysmon, PowerShell Script Block, WMI Activity, Task Scheduler, VPN, firewall, EDR, vCenter, backup, and identity provider events.
- Deploy or tune the Sigma and KQL detections above; create high-severity alerts for shadow copy deletion, backup catalog deletion, PsExec service creation, rclone/7z staging, and mass logon failure followed by success.
- Lock down developer tooling: remove unused IDE extensions, verify package integrity, pin versions, and monitor build agents for unexpected outbound connections.
Short-term — 2 weeks
- Segment management planes: vCenter, backup, EDR, firewall management, CI/CD, and storage admin interfaces should be reachable only from hardened PAWs/jump hosts with just-in-time elevation.
- Move to immutable, isolated backups with separate credentials, offline or object-lock copies, and quarterly restore tests that include authentication and application dependencies.
- Implement egress control by default-deny for servers, allowlisting required update and business services; alert on rare cloud storage, file-sharing, and newly seen domains.
- Reduce standing privilege with tiered admin, LAPS, gMSA where appropriate, automatic rotation of service accounts, and detection for additions to privileged groups.
- Establish leak-site and extortion monitoring runbooks so claims are triaged quickly without confirming or denying publicly before evidence review.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.