Storm-0530
Actor Type | Nation State |
---|---|
Attributed to Nation | North Korea |
Directly Linked Intrusion Sets | H0lyGh0st |
Affiliated Intrusion Sets | Onyx Sleet |
Storm-0530 is an intrusion set tracked by researchers at Microsoft Threat Intelligence. The group calls itself H0lyGh0st and conducts ransomware attacks for financial gain on behalf of the North Korea.
The group has been observed deploying a ransomware payload which encrypts files and appends the '.h0lyenc' file extension. Victim communication is then conducted through a .onion Tor site with threats to leak exfiltrated data as well as requiring payment to decrypt files.
Microsoft suggest the group is distinct from but affiliated with Onyx Sleet (also known as Andariel / DarkSeoul).
Cyber Threat Graph Context
Explore how this Intrusion Set relates to the wider threat graph