H0lyGh0st, also known as HolyGhost, is a DPRK-linked ransomware operation and malware family active since 2021. It is financially motivated and uses double extortion: operators obtain access to victim environments, move within the network, exfiltrate data, encrypt files, and threaten public disclosure of stolen information to pressure victims into paying cryptocurrency ransoms. Reported targets have primarily been small and midsize organizations, including entities in financial services, manufacturing, education, and entertainment. H0lyGh0st activity has been associated with the North Korean DEV-0530 cluster and has demonstrated operational overlaps with Andariel, also tracked as Onyx Sleet. Known payload evolution includes an early C++ implementation and later Go-based variants. The ransomware has exploited vulnerabilities in public-facing applications, including CVE-2022-26352, for initial access. Observed variants obfuscate strings, alter encrypted filenames, deploy ransom notes, and may establish persistence through scheduled tasks. Some variants can use internal network resources as fallback infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Recently observed CVEs that actors used to gain access include ... remote code execution in unpatched SonicWall SMA 100 appliances... Observed CVEs used include: CVE-2021-20038
Recently observed CVEs that actors used to gain access include remote code execution in the Apache Log4j software library (known as Log4Shell)... Observed CVEs used include: CVE-2021-44228
Observed CVEs used include: ... CVE-2022-24990 ... The TerraMaster OS Unauthenticated Remote Command Execution via PHP Object Instantiation Vulnerability is characterized by scanning activity targeting a flaw...
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"Andariel is particular as it used custom ransomware (Maui and H0lyGh0st) for financial theft."
Lazarus Group has historically deployed its own ransomware families -- Maui, H0lyGh0st, and WannaCry.
the cybercriminal group which developed the H0lyGh0st ransomware is assessed to be originating from the DPRK
Microsoft reported on Onyx Sleet’s and Storm-0530’s h0lyGhost ransomware in 2022.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
"...remote code execution in unpatched SonicWall SMA 100 appliances [T1190 and T1133]."
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom ransomware used by Andariel for financially motivated theft.
Ransomware family previously deployed by Andariel, mentioned as background context.
Referenced as a prior Lazarus-operated ransomware family historically built and controlled by the group.
H0lyGh0st is cited as a ransomware family historically deployed by Lazarus Group.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.