North Korean threat actor targets small and midsize businesses with H0lyGh0st ransomware
2022-07-14 • Microsoft •
Microsoft attributed H0lyGh0st ransomware activity to DEV-0530, a North Korea-origin threat cluster later tracked as Storm-0530, and observed compromises of small and midsize businesses in multiple countries from at least September 2021. The group encrypted Windows systems, used the .h0lyenc extension, demanded Bitcoin payments, and threatened to publish or share victim data if ransoms were not paid. Microsoft assessed likely overlap with the North Korea-based PLUTONIUM group, also known as DarkSeoul or Andariel, based on shared infrastructure, communications between known accounts, and DEV-0530 use of tools created exclusively by PLUTONIUM. The ransomware families SiennaPurple and SiennaBlue included variants such as BTLC_C.exe, HolyRS.exe, HolyLock.exe, and BLTC.exe, with common C2 infrastructure and HTTP beacon patterns including access.php?order=AccessRequest&cmn. The activity matters because it links North Korea-origin operators to financially motivated ransomware tradecraft while distinguishing DEV-0530 from PLUTONIUM in tempo, targeting, and tooling.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 99fc54786a72f32fd44c7391c2171ca… | 2022-07-14 | 2024-03-17 |
| [email protected] | 2022-07-14 | 2024-03-17 | |
| DOMAIN | mail2tor.com | 2022-07-14 | 2024-03-17 |
| DOMAIN | matmq3z3hiovia3voe2tix2x54sghc3… | 2022-07-14 | 2024-03-17 |
| HASH | 541825cb652606c2ea12fd25a842a8b… | 2022-07-14 | 2023-02-09 |
| HASH | bea866b327a2dc2aa104b7ad7307008… | 2022-07-14 | 2023-02-09 |
| HASH | f8fc2445a9814ca8cf48a979bff7f18… | 2022-07-14 | 2023-02-09 |
| URL | http://matmq3z3hiovia3voe2tix2x… | 2022-07-14 | 2022-08-30 |
| IPv4 | 193.56.29.123 | 2022-07-14 | 2022-08-30 |
| YARA | SiennaBlue | 2022-07-14 | 2022-07-14 |
| YARA | SiennaPurple | 2022-07-14 | 2022-07-14 |
| HASH | f44c6929994386ac2ae18b93f8270ec… | 2022-07-14 | 2022-07-14 |
| URL | https://cloud-ex42.usaupload.co… | 2022-07-14 | 2022-07-14 |
| DOMAIN | cloud-ex42.usaupload.com | 2022-07-14 | 2022-07-14 |