News Room
16
Share
Storm Ransomware Targets Phoenix Group of Companies Amid Surge in RaaS Activity
highThreat Intelligence

Storm Ransomware Targets Phoenix Group of Companies Amid Surge in RaaS Activity

The emerging Storm ransomware group has claimed responsibility for a significant breach of the Phoenix Group of Companies, highlighting a shift toward targeting mid-market industrial conglomerates.

25 August 2026Last updated 25 August 20264 min readUnit 42
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Threat Intelligence
Severity:
High
Actor Type:
Ransomware Group
Geography:
North America
Confidence:
High Confidence
CVE:
CVE-2024-21887
Source:
Unit 42
Read Time:
4 min

Executive Summary

On August 24, 2026, the emerging threat actor known as the Storm ransomware group publicly claimed responsibility for a cyberattack against the Phoenix Group of Companies, a U.S.-based industrial conglomerate. This incident follows a weekend of heightened activity in the Ransomware-as-a-Service (RaaS) ecosystem, which also saw the The Gentlemen group target Chilean construction firm Espac and Coinbasecartel breach Westwing Group SE. These events, coupled with a major CISA advisory on Medusa Ransomware released on August 25, 2026, underscore a volatile threat landscape where nascent groups are rapidly scaling operations to target critical supply chain entities.

Threat Analysis

The Storm ransomware group is a relatively new entrant in the 2026 threat landscape. Unlike established giants like LockBit or Qilin, Storm appears to be specializing in mid-market industrial and healthcare targets. Intelligence suggests the group utilizes a double-extortion model, exfiltrating sensitive corporate data before deploying encryption payloads. The attack on Phoenix Group indicates a sophisticated understanding of industrial organizational structures, likely aimed at maximizing operational disruption to force rapid payouts. This aligns with broader Q3 2026 trends where ransomware incidents have risen 55% year-over-year, driven by a proliferation of specialized RaaS affiliates.

Technical Details

Preliminary forensic analysis of recent Storm and The Gentlemen activities suggests a heavy reliance on EDR kill techniques and the exploitation of unpatched edge vulnerabilities. Specifically, threat actors have been observed chaining vulnerabilities such as CVE-2024-21887 and recent SonicWall zero-days to gain initial access. Once inside, the actors deploy tools like SystemBC for persistence and use BYOVD (Bring Your Own Vulnerable Driver) tactics to disable security software. In the Phoenix Group case, the attackers reportedly targeted internal file servers and backup repositories, attempting to delete shadow copies to prevent local recovery before initiating the encryption phase.

Attribution Assessment

Attribution for the Storm group remains in the 'moderate' confidence category. While some indicators of compromise (IOCs) overlap with older Conti or Black Basta playbooks, the group's infrastructure appears distinct. Conversely, The Gentlemen group has been linked by researchers at FortiGuard to Iranian-aligned interests, often targeting energy and government sectors. The emergence of 'Ransom Busters'—third-party actors claiming to hack ransomware servers to delete stolen data for a fee—further complicates the attribution landscape, as these entities may actually be affiliates of the original RaaS groups operating under a different guise.

Implications

The breach of Phoenix Group of Companies highlights the cascading risks inherent in industrial supply chains. As these conglomerates often provide essential components to larger infrastructure projects, a disruption in their IT/OT environments can lead to significant downstream delays. Furthermore, the August 25 CISA advisory on Medusa Ransomware confirms that RaaS groups are increasingly leveraging 'white-label' models, allowing less-skilled affiliates to deploy high-grade malware, thereby increasing the total volume of global attacks.

Recommendations

Encrygma recommends that organizations immediately prioritize the following: 1. Immutable Backups: Ensure all critical data is stored in write-once-read-many (WORM) environments that are logically air-gapped from the primary network. 2. EDR Hardening: Implement tamper-protection features and monitor for unauthorized driver loads (BYOVD). 3. Vulnerability Management: Patch critical edge devices, specifically SonicWall and Citrix appliances, within 24 hours of disclosure. 4. Threat Hunting: Scan for IOCs related to Storm and The Gentlemen, focusing on anomalous PowerShell execution and unauthorized use of Rclone or WinSCP for data exfiltration.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo