Also known as: DEV-0530, H0lyGh0st
H0lyGh0st is a North Korean threat actor that has been active since June 2021. They are responsible for developing and deploying the H0lyGh0st ransomware, which targets small-to-medium businesses in various sectors. The group employs "double extortion" tactics, encrypting data and threatening to publish it if the ransom is not paid. There are connections between H0lyGh0st and the PLUTONIUM APT group, indicating a possible affiliation.
Executive Summary
Storm-0530, also known as H0lyGh0st and DEV-0530, is a North Korean-linked threat actor active since June 2021. They primarily target small-to-medium businesses across various sectors with the H0lyGh0st ransomware using double extortion tactics—encrypting data and threatening to leak it unless a ransom is paid. The group’s operations suggest a focus on financial gain, aligning with their suspected APT origins.
Goals & Targeting
Storm-0530 appears motivated by financial gain, targeting SMEs where ransom payments are feasible and less likely to be reported. Their geographic focus is broad, with victims identified in multiple countries, implying a global reach. The double extortion strategy underscores their intent to maximize revenue from each attack.
Enhanced Description
Storm-0530, operating under the aliases H0lyGh0st and DEV-0530, represents a North Korean threat actor observed since June 2021. The group is notable for deploying the H0lyGh0st ransomware, which employs double extortion tactics to maximize受害者压力. Their primary targets are small-to-medium enterprises (SMEs) across various sectors, reflecting a strategic focus on organizations that may lack robust defenses and are more likely to pay ransoms. The group’s connection to the PLUTONIUM APT suggests a possible affiliation or shared operational origins within North Korea's cyber espionage ecosystem.
Key Capabilities
Software / Tooling
Campaigns & Victims
Storm-0530’s campaigns typically involve targeting SMEs across diverse sectors using phishing and other attack vectors. Their operational tempo suggests a focus on steady financial returns rather than high-profile attacks, which makes them a significant yet undertheorized threat globally. Notable for their linkage to the PLUTONIUM APT group, indicating potential state-sponsored ties.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the identification of Storm-0530 as H0lyGh0st is high, supported by descriptive and contextual data linking them to North Korea. However, specific TTPs (tactics, techniques, procedures) remain unclear, particularly regarding their initial infection vectors beyond phishing.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics