H0lyGh0st, also tracked as Storm-0530, is a North Korea-linked threat actor associated with ransomware operations and assessed to have affiliations with Onyx Sleet. The actor is known for operating the H0lyGh0st ransomware and has been observed sharing infrastructure and maintaining operational links with Onyx Sleet, including interaction with Onyx Sleet-controlled accounts and use of similarly named custom malware controllers. H0lyGh0st activity has been observed since at least September 2021 and has targeted small organizations in multiple countries, including very small businesses and educational institutions. Reported victims have included small schools and small private-sector organizations. The actor’s operations are notable for ransomware deployment against comparatively low-scale targets rather than large enterprise victims. The group’s tradecraft, as directly supported here, centers on ransomware-based intrusion and extortion. H0lyGh0st is the name used by the operators themselves on their ransom infrastructure. Microsoft has described the actor as distinct but affiliated with Onyx Sleet, another long-running North Korean actor, with overlap in infrastructure and communications. These links place Storm-0530 within the broader ecosystem of DPRK cyber operations. The dominant motivation reflected in the reporting is financial gain. Although North Korean cyber activity often overlaps with state objectives, the directly supported characterization for Storm-0530 in this context is ransomware activity conducted for revenue generation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 malware families attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.