HolyGhost (tracked by Microsoft as DEV-0530) is a North Korean state-linked ransomware group active since June 2021, associated with the Andariel threat group, targeting small to mid-sized businesses in financial services, manufacturing, education, and entertainment globally.
Objectives
Executive Summary
HolyGhost, tracked by Microsoft as DEV-0530, is a North Korean state-linked ransomware group active since June 2021. Associated with the Andariel threat group, they target small to mid-sized businesses globally across financial services, manufacturing, education, and entertainment sectors for financial gain.
Goals & Targeting
HolyGhost's primary goal is financial gain through ransomware activities. They target small to mid-sized businesses globally, focusing on sectors where data value and potential for disruption are high. Their global targeting suggests a focus on broad victim pools rather than specific regions or industries, though operations may have particular concentrations in certain countries. The group likely targets SMEs due to weaker defenses and higher susceptibility to their attack methods.
Enhanced Description
HolyGhost, known as DEV-0530 by Microsoft, is a North Korean state-linked ransomware group active since June 2021. They operate in association with the Andariel threat group, which has historical ties to various cyberattacks. HolyGhost primarily targets small to mid-sized businesses globally across sectors like financial services, manufacturing, education, and entertainment. Their ransomware campaigns often involve double extortion tactics, encrypting victims' data and demanding ransoms, sometimes seeking cryptocurrency for decryption keys. Notable attacks have been tracked by Microsoft, with victims facing significant recovery costs due to data encryption.
Key Capabilities
MITRE ATT&CK Tactics
Campaigns & Victims
HolyGhost consistently targets SMEs with ransomware, leveraging their often-limited security measures. Campaigns often involve initial phishing emails leading to malware deployment, followed by network traversal and data encryption. Microsoft's tracking efforts have identified several attacks linked to this group since mid-2021, highlighting their operational persistence.
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in HolyGhost's profile, with gaps remaining in specific TTPs and tools used. Lacking detailed IOC data hinders precise threat detection.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics