H0lyGh0st
H0lyGh0st, also known as HolyGhost and DEV-0530, is a North Korea-based financially motivated cyber extortion and ransomware group active since June 2021. Microsoft also refers to this cluster as Storm-0530. The group has primarily targeted small-to-midsize organizations, including entities in financial services, manufacturing, education, and entertainment. H0lyGh0st conducts double-extortion ransomware operations: it gains initial access, moves laterally, exfiltrates data, encrypts files, and demands payment while threatening to leak stolen data. It has operated a .onion site to communicate with victims, threatened publication of stolen data on platforms such as Pastebin, and sent victims samples of stolen data as proof of compromise. Reported ransom demands ranged from 1.2 to 5 BTC, with some victims reportedly negotiating reductions. The group has been described as exploiting vulnerabilities in public-facing web applications and content management systems for initial access, including DotCMS remote code execution vulnerability CVE-2022-26352. Its ransomware variants include the early C++ sample BTLC_C.exe, associated with the SiennaPurple family, and later Go-based variants HolyRs.exe, HolyLock.exe, and BLTC.exe, associated with the SiennaBlue family. Reported behaviors include Base64-encoding filenames, appending the .h0lyenc extension, and dropping a ransom note named FOR_DECRYPT.html. The BLTC.exe variant has been described as using a hardcoded intranet URL and ServerBaseUrl, falling back to a network share with default credentials, and creating and deleting a scheduled task named lockertask for persistence. Microsoft Threat Intelligence Center reported overlaps between H0lyGh0st and PLUTONIUM, also known as Andariel and DarkSeoul, a subgroup under the Lazarus umbrella, based on observed communications and similar custom malware controllers. The content describes H0lyGh0st as North Korea-based and notes this possible affiliation, but does not state a definitive merger or identical attribution.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Where they're from
Attributed origin per open-source reporting.
- KP
Associated malware families
5 malware families attributed to this actor across reporting.
Associated vulnerabilities
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
Observables
11 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
North Korea-linked threat actor cluster listed in Microsoft's naming taxonomy mapping.
North Korea-linked financially motivated cyber extortion activity conducting ransomware and double-extortion operations primarily against small-to-midsize organizations; develops and deploys custom ransomware variants (BTLC_C.exe, HolyRs.exe, HolyLock.exe, BLTC.exe) and uses data theft plus encryption to coerce payment.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.