North Korean threat actor targets small and midsize businesses with H0lyGh0st ransomware

2022-07-14 Microsoft

https://www.microsoft.com/security/blog/2022/07/14/north-korean-threat-actor-targets-small-and-midsize-businesses-with-h0lygh0st-ransomware/

Thumbnail for North Korean threat actor targets small and midsize businesses with H0lyGh0st ransomware

Microsoft attributed H0lyGh0st ransomware activity to DEV-0530, a North Korea-origin threat cluster later tracked as Storm-0530, and observed compromises of small and midsize businesses in multiple countries from at least September 2021. The group encrypted Windows systems, used the .h0lyenc extension, demanded Bitcoin payments, and threatened to publish or share victim data if ransoms were not paid. Microsoft assessed likely overlap with the North Korea-based PLUTONIUM group, also known as DarkSeoul or Andariel, based on shared infrastructure, communications between known accounts, and DEV-0530 use of tools created exclusively by PLUTONIUM. The ransomware families SiennaPurple and SiennaBlue included variants such as BTLC_C.exe, HolyRS.exe, HolyLock.exe, and BLTC.exe, with common C2 infrastructure and HTTP beacon patterns including access.php?order=AccessRequest&cmn. The activity matters because it links North Korea-origin operators to financially motivated ransomware tradecraft while distinguishing DEV-0530 from PLUTONIUM in tempo, targeting, and tooling.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 99fc54786a72f32fd44c7391c2171ca… 2022-07-14 2024-03-17
EMAIL [email protected] 2022-07-14 2024-03-17
DOMAIN mail2tor.com 2022-07-14 2024-03-17
DOMAIN matmq3z3hiovia3voe2tix2x54sghc3… 2022-07-14 2024-03-17
HASH 541825cb652606c2ea12fd25a842a8b… 2022-07-14 2023-02-09
HASH bea866b327a2dc2aa104b7ad7307008… 2022-07-14 2023-02-09
HASH f8fc2445a9814ca8cf48a979bff7f18… 2022-07-14 2023-02-09
URL http://matmq3z3hiovia3voe2tix2x… 2022-07-14 2022-08-30
IPv4 193.56.29.123 2022-07-14 2022-08-30
YARA SiennaBlue 2022-07-14 2022-07-14
YARA SiennaPurple 2022-07-14 2022-07-14
HASH f44c6929994386ac2ae18b93f8270ec… 2022-07-14 2022-07-14
URL https://cloud-ex42.usaupload.co… 2022-07-14 2022-07-14
DOMAIN cloud-ex42.usaupload.com 2022-07-14 2022-07-14

Related Actors

Related Reports

« Back