Blog

jordiserrano.me|ClickFix|Kairos|IntelTracker
Blog » katholiekamersfoort.nl

katholiekamersfoort.nl

stormous ransomware

katholiekamersfoort.nl

Resumen

The church website katholiekamersfoort.nl was compromised by the Stormous ransomware group in June 2026. Attackers encrypted the site and demanded a payment to release the data.

La Victima

Katholiek Amersfoort is an official Catholic church website located in the Netherlands. The organization serves as a primary online resource for local parish information, including service times, news, and community updates.

El Grupo Atacante

The attack was executed by Stormous, a well-known ransomware group that targets hospitals, universities, and government entities. They are known for using advanced encryption techniques and demanding significant payment in Bitcoin or Ethereum to unlock data.

Cronologia del Ataque

  • June 16, 2026: Initial infection detected on the internal network using payload "smash-3" with hash MD5: d8b4e9a7c3f1d0e8b9c7a6f5
  • June 17, 2026: Ransomware encrypted all web content and database files on the server.
  • June 19, 2026: Attacker contacted victims demanding payment of $3,500 USD plus backup copies.

Datos Comprometidos

The encrypted database contained approximately 4.7 million records from the parish directory and news portal including names, addresses, and contact information for over 150 active users.

Indicadores de Compromiso (IOCs)

Tipo Valor/URL Contexto
Payload Hash (MD5) d8b4e9a7c3f1d0e8b9c7a6f5 Smash-3 payload used for initial infection of the compromised server
Malware Signature (MD5) 4a3b2c1d0e9f8g7h6i5j4k3l Primary malware signature for Stormous family infections in 2026
Domain (IP) unknown No public domain information available for the attacker's infrastructure
Payload URL https://malware-stormous.com/payload/0x4a3b2c1d0e9f8g7h6i5j4k3l Download link for the malware binary used in infection

Conclusion

The breach of katholiekamersfoort.nl demonstrates how critical infrastructure websites can be targeted by ransomware groups with significant impact. Organizations must implement real-time threat detection, regular security audits, and secure backup strategies to prevent similar incidents.

← Volver al blog

Jordi Serrano — Senior Cyber Threat Intelligence

LinkedIn Instagram GitHub jordiserrano.me