#SiennaPurple

Malware/Tool

2022-07-14 • North Korean threat actor targets small and midsize businesses with H0lyGh0st ransomware

SiennaPurple is a ransomware family developed and used by DEV-0530 in H0lyGh0st campaigns. Its BTLC_C.exe variant is a portable C++ encryptor that requires administrative privileges, obfuscates strings, and shares command-and-control infrastructure and request patterns with SiennaBlue variants.

Tagged Reports

« Back