DEV-0530

2022-07-14 • MicrosoftNorth Korean threat actor targets small and midsi…

DEV-0530 is a North Korea-based threat group first documented by Microsoft's MSTIC in a July 2022 report, which had tracked the group developing and using H0lyGh0st ransomware since June 2021, with confirmed victim compromises beginning around September 2021 (Microsoft later renamed the group Storm-0530 under an April 2023 weather-themed taxonomy update). The group primarily pursues financial objectives, encrypting victim files after exfiltrating data, then demanding Bitcoin payment while threatening to publish stolen data if victims refuse to pay; it operates a Tor-based site for victim communication. Victims were mainly small and midsize businesses across multiple countries, including manufacturing firms, banks, schools, and event-planning companies, suggesting opportunistic targets of opportunity; the group has been observed exploiting a web application remote-code-execution vulnerability for initial access, without use of zero-days. MSTIC assessed likely connections between DEV-0530 and the North Korean group PLUTONIUM, including shared infrastructure, communications, and tooling, though operational tempo and targeting differences suggest they remain distinct groups; activity timing was consistent with North Korean time zones.

Related Actors

First seen: Jul 2017
Last seen: Jun 2026

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster