Storm-0530

Aliases: DEV-0530, H0lyGh0st

First seen
2021-06-01 00:00:00
Origin
KP
Primary motivation
financial-gain
Sophistication
intermediate
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:05:14

Targeted industries: manufacturing professional-services technology-and-telecommunications

Context

H0lyGh0st is a North Korean threat actor that has been active since June 2021. They are responsible for developing and deploying the H0lyGh0st ransomware, which targets small-to-medium businesses in various sectors. The group employs "double extortion" tactics, encrypting data and threatening to publish it if the ransom is not paid. There are connections between H0lyGh0st and the PLUTONIUM APT group, indicating a possible affiliation.

Reports & references

  • ics-cert.kaspersky.com — Apt Attacks On Industrial Organizations In H2 2022 (report)
  • CISA — Aa23 040A (report)
  • blogs.blackberry.com — H0Lygh0St Ransomware (report)
  • Microsoft — North Korean Threat Actor Targets Small And Midsize Businesses With H0Lygh0St Ransomware (report)
  • picussecurity.com — H0Lygh0St North Korean Threat Group Strikes Back With New Ransomware (report)
  • Microsoft — Microsoft Threat Actor Naming (report)

External references