HolyGhost is a Windows ransomware family associated with North Korean threat activity and publicly linked to operations attributed to Dark Seoul. It has been observed in financially motivated intrusions, including attacks against government environments, where operators used compromised or privileged accounts, scheduled tasks, and Windows services to deploy the ransomware across multiple systems. In documented intrusions, HolyGhost was part of broader post-compromise activity that also included disabling Microsoft Defender protections, credential dumping, network scanning, tool transfer with PowerShell, and deployment of additional monetization tooling such as cryptominers.
HolyGhost encrypts victim files using AES and appends a distinctive encrypted-file extension. It has been reported to retrieve a public key from attacker-controlled infrastructure as part of its encryption workflow. Operationally, it has been observed creating scheduled-task persistence or execution mechanisms running at high privilege, including recurring execution as SYSTEM. The malware is part of a wider pattern of North Korean ransomware use alongside other families such as Maui and PLAY, reflecting the overlap between state-linked intrusion tradecraft and revenue-generating cybercrime.
Observed victimology includes government-sector targets, and the surrounding intrusion activity indicates use in enterprise-wide compromises rather than opportunistic single-host infections. High-confidence reporting supports HolyGhost as a ransomware payload used after successful access and lateral movement within Windows networks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The attackers gained initial access by exploiting the vulnerability CVE-2021-44228 (Log4Shell) in VMware Horizon. | the attackers used a privileged account to run various files on the system and to run a malicious file known as HolyGhost Ransomware.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The HolyGhost ransomware spread by the APT group known as Dark Seoul also created a task using schtasks.exe. | the attackers used a privileged account to run various files on the system and to run a malicious file known as HolyGhost Ransomware.
North Korean threat actors have previously been linked to other ransomware strains such as HolyGhost, PLAY, Maui, Qilin...
12 distinct techniques documented for this family, organized by ATT&CK tactic.
This complex type of startup is a technique known as Obfuscated Files or Information T1027.
While employing the Process Hollowing technique, an attacker is often disguised as a legitimate process (Masquerading T1036).
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware strain previously linked to North Korean threat actors (per the article).
Ransomware strain previously linked to North Korean threat actors.
Go-based ransomware that encrypts user files, can disable shares, create/delete services, create scheduled tasks on remote machines, and retrieve a public encryption key from its C2 over HTTP.
Ransomware observed creating scheduled tasks for persistence/execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.