Storm-0530

Actor Type Nation State
Attributed to Nation North Korea
Directly Linked Intrusion Sets H0lyGh0st
Affiliated Intrusion Sets Onyx Sleet

Storm-0530 is an intrusion set tracked by researchers at Microsoft Threat Intelligence. The group calls itself H0lyGh0st and conducts ransomware attacks for financial gain on behalf of the North Korea.

The group has been observed deploying a ransomware payload which encrypts files and appends the '.h0lyenc' file extension. Victim communication is then conducted through a .onion Tor site with threats to leak exfiltrated data as well as requiring payment to decrypt files.

Microsoft suggest the group is distinct from but affiliated with Onyx Sleet (also known as Andariel / DarkSeoul).

Cyber Threat Graph Context

Explore how this Intrusion Set relates to the wider threat graph

References