H0lyGh0st Ransomware

#H0lyGh0st • 2022-07

🇺🇸 United States

DEV-0530, a North Korea-origin ransomware cluster with suspected overlap with PLUTONIUM/Andariel tooling and infrastructure, used H0lyGh0st ransomware against small and midsize businesses from at least September 2021. The campaign encrypted Windows systems with SiennaPurple and SiennaBlue variants, used the .h0lyenc extension, demanded Bitcoin payments, and applied double-extortion pressure by threatening to publish or share victim data.

Related Actors

DEV-0530

Microsoft

DEV-0530 is a North Korea-based threat group first documented by Microsoft's MSTIC in a July 2022 report, which had tracked the group developing and using H0lyGh0st ransomware since June 2021, with confirmed victim compromises beginning around September 2021 (Microsoft later renamed the group Storm-0530 under an April 2023 weather-themed taxonomy update). The group primarily pursues financial objectives, encrypting victim files after exfiltrating data, then demanding Bitcoin payment while threatening to publish stolen data if victims refuse to pay; it operates a Tor-based site for victim communication. Victims were mainly small and midsize businesses across multiple countries, including manufacturing firms, banks, schools, and event-planning companies, suggesting opportunistic targets of opportunity; the group has been observed exploiting a web application remote-code-execution vulnerability for initial access, without use of zero-days. MSTIC assessed likely connections between DEV-0530 and the North Korean group PLUTONIUM, including shared infrastructure, communications, and tooling, though operational tempo and targeting differences suggest they remain distinct groups; activity timing was consistent with North Korean time zones.

North Korean threat actor targets small and midsi…
Associated with: Plutonium
First seen: 2022-07 • Last seen: 2022-11

Related Reports

« Back