Storm-0530 is a North Korean threat actor known for H0lyGh0st ransomware and double extortion attacks.
Analyst brief
Storm-0530 (also known as H0lyGh0st) is a North Korean threat actor active since June 2021, known for developing the H0lyGh0st ransomware. It primarily targets small-to-medium businesses across various sectors using double extortion tactics, encrypting data and threatening to publish it. Observed TTPs include the deployment of custom ransomware and potential links to the PLUTONIUM APT group. Defenders should focus on monitoring for data exfiltration, ensuring robust backup integrity, and guarding against targeted phishing attempts that may lead to network compromise.
Storm-0530
DEV-0530H0lyGh0st
unknown
H0lyGh0st is a North Korean threat actor that has been active since June 2021. They are responsible for developing and deploying the H0lyGh0st ransomware, which targets small-to-medium businesses in various sectors. The group employs "double extortion" tactics, encrypting data and threatening to publish it if the ransom is not paid. There are connections between H0lyGh0st and the PLUTONIUM APT group, indicating a possible affiliation.