Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Storm-0530

Also known as: DEV-0530, H0lyGh0st

Description

H0lyGh0st is a North Korean threat actor that has been active since June 2021. They are responsible for developing and deploying the H0lyGh0st ransomware, which targets small-to-medium businesses in various sectors. The group employs "double extortion" tactics, encrypting data and threatening to publish it if the ransom is not paid. There are connections between H0lyGh0st and the PLUTONIUM APT group, indicating a possible affiliation.

AI Analysis

· 1 week ago

Executive Summary

Storm-0530, also known as H0lyGh0st and DEV-0530, is a North Korean-linked threat actor active since June 2021. They primarily target small-to-medium businesses across various sectors with the H0lyGh0st ransomware using double extortion tactics—encrypting data and threatening to leak it unless a ransom is paid. The group’s operations suggest a focus on financial gain, aligning with their suspected APT origins.

Goals & Targeting

Storm-0530 appears motivated by financial gain, targeting SMEs where ransom payments are feasible and less likely to be reported. Their geographic focus is broad, with victims identified in multiple countries, implying a global reach. The double extortion strategy underscores their intent to maximize revenue from each attack.

Enhanced Description

Storm-0530, operating under the aliases H0lyGh0st and DEV-0530, represents a North Korean threat actor observed since June 2021. The group is notable for deploying the H0lyGh0st ransomware, which employs double extortion tactics to maximize受害者压力. Their primary targets are small-to-medium enterprises (SMEs) across various sectors, reflecting a strategic focus on organizations that may lack robust defenses and are more likely to pay ransoms. The group’s connection to the PLUTONIUM APT suggests a possible affiliation or shared operational origins within North Korea's cyber espionage ecosystem.

Key Capabilities

  • Development and deployment of H0lyGh0st ransomware
  • Double extortion tactics combining data encryption with leak threats
  • Potential use of APT-style espionage tools as part of campaigns

Software / Tooling

H0lyGh0st Ransomware
PLUTONIUM group-associated tools (possibly Cobalt Strike)
Custom malicious software

Campaigns & Victims

Storm-0530’s campaigns typically involve targeting SMEs across diverse sectors using phishing and other attack vectors. Their operational tempo suggests a focus on steady financial returns rather than high-profile attacks, which makes them a significant yet undertheorized threat globally. Notable for their linkage to the PLUTONIUM APT group, indicating potential state-sponsored ties.

IOC Patterns

  • Presence of H0lyGh0st ransomware encryption patterns
  • Lateral movement and privilege escalation within networks
  • Use of Cobalt Strike-like tools for initial access

Recommended Actions

  • Implement multi-factor authentication (MFA) for all remote access points
  • Enhance email filtering and detection for suspicious phishing attempts
  • Monitor network traffic for signs of lateral movement and unusual behavior
  • Conduct regular backups and store them offline to mitigate ransomware impacts

Suggested Tags

APT
Ransomware
Double extortion
Financial motivation
SME targeting
North Korean Origin

Confidence Assessment

Confidence in the identification of Storm-0530 as H0lyGh0st is high, supported by descriptive and contextual data linking them to North Korea. However, specific TTPs (tactics, techniques, procedures) remain unclear, particularly regarding their initial infection vectors beyond phishing.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
APT
Critical Infrastructure
Double extortion
Financial motivation
SME targeting
North Korean Origin

Details

Type
Unknown
Country of Origin
K
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.