H0lyGh0st is a Windows ransomware family used by a North Korea-based extortion group tracked by Microsoft as Storm-0530, formerly DEV-0530. Active since at least June 2021, the operation has compromised small and midsize organizations across multiple countries, including manufacturing, financial services, education, and entertainment businesses. Its double-extortion workflow combines data theft with file encryption and demands for bitcoin payments, backed by threats to publish stolen information. The operators have documented infrastructure, communications, and tooling overlaps with Andariel, also known as Onyx Sleet, without the two groups necessarily being identical.
Early H0lyGh0st payloads, classified as SiennaPurple, were written in C++; later SiennaBlue variants were developed in Go and share encryption, key-management, and networking functionality. The ransomware encodes filenames with Base64, marks encrypted files, and creates a ransom note. Some variants use string obfuscation, while later variants support scheduled-task persistence and fallback communication through internal network resources. The operators exploit vulnerable public-facing applications to obtain access before deploying ransomware. H0lyGh0st is among the privately developed ransomware families associated with DPRK-linked financially motivated cyber operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Recently observed CVEs that actors used to gain access include ... remote code execution in unpatched SonicWall SMA 100 appliances... Observed CVEs used include: CVE-2021-20038
Recently observed CVEs that actors used to gain access include remote code execution in the Apache Log4j software library (known as Log4Shell)... Observed CVEs used include: CVE-2021-44228
Observed CVEs used include: ... CVE-2022-24990 ... The TerraMaster OS Unauthenticated Remote Command Execution via PHP Object Instantiation Vulnerability is characterized by scanning activity targeting a flaw...
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Andariel est notable pour l’utilisation des ransomwares personnalisés Maui et H0lyGh0st, ainsi que du RaaS Play en 2024.
Lazarus Group has historically deployed its own ransomware families -- Maui, H0lyGh0st, and WannaCry.
the cybercriminal group which developed the H0lyGh0st ransomware is assessed to be originating from the DPRK
Microsoft reported on Onyx Sleet’s and Storm-0530’s h0lyGhost ransomware in 2022.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
"...remote code execution in unpatched SonicWall SMA 100 appliances [T1190 and T1133]."
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom ransomware used by the North Korean-linked Andariel group.
Custom ransomware used by Andariel for financially motivated theft.
Ransomware family previously deployed by Andariel, mentioned as background context.
Referenced as a prior Lazarus-operated ransomware family historically built and controlled by the group.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.