Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors holyghost

Description

HolyGhost (tracked by Microsoft as DEV-0530) is a North Korean state-linked ransomware group active since June 2021, associated with the Andariel threat group, targeting small to mid-sized businesses in financial services, manufacturing, education, and entertainment globally.

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

HolyGhost, tracked by Microsoft as DEV-0530, is a North Korean state-linked ransomware group active since June 2021. Associated with the Andariel threat group, they target small to mid-sized businesses globally across financial services, manufacturing, education, and entertainment sectors for financial gain.

Goals & Targeting

HolyGhost's primary goal is financial gain through ransomware activities. They target small to mid-sized businesses globally, focusing on sectors where data value and potential for disruption are high. Their global targeting suggests a focus on broad victim pools rather than specific regions or industries, though operations may have particular concentrations in certain countries. The group likely targets SMEs due to weaker defenses and higher susceptibility to their attack methods.

Enhanced Description

HolyGhost, known as DEV-0530 by Microsoft, is a North Korean state-linked ransomware group active since June 2021. They operate in association with the Andariel threat group, which has historical ties to various cyberattacks. HolyGhost primarily targets small to mid-sized businesses globally across sectors like financial services, manufacturing, education, and entertainment. Their ransomware campaigns often involve double extortion tactics, encrypting victims' data and demanding ransoms, sometimes seeking cryptocurrency for decryption keys. Notable attacks have been tracked by Microsoft, with victims facing significant recovery costs due to data encryption.

Key Capabilities

  • Ransomware distribution
  • Double extortion tactics
  • Phishing campaigns

MITRE ATT&CK Tactics

Ransomware Preparation
Payload Delivery
Lateral Movement

Campaigns & Victims

HolyGhost consistently targets SMEs with ransomware, leveraging their often-limited security measures. Campaigns often involve initial phishing emails leading to malware deployment, followed by network traversal and data encryption. Microsoft's tracking efforts have identified several attacks linked to this group since mid-2021, highlighting their operational persistence.

Recommended Actions

  • Enhance user training on spotting phishing attempts
  • Implement robust network monitoring tools
  • Regularly back up critical data and isolate backups
  • Deploy endpoint detection and response (EDR) solutions

Suggested Tags

APT
ransomware
espionage
finance-sector
manufacturing-sector

Confidence Assessment

Moderate confidence in HolyGhost's profile, with gaps remaining in specific TTPs and tools used. Lacking detailed IOC data hinders precise threat detection.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
APT
ransomware
espionage
finance-sector
manufacturing-sector

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.