North Korean Hackers Targets Businesses With H0lyGh0st Ransomware

Share post:

A group of North Korean hackers called H0lyGh0st are targeting small and medium-sized enterprises with ransomware attacks.

Microsoft Threat Intelligence Center classify the group as DEV-0530, a term for unknown emerging, or an evolving group of threat activities.

DEV-0530 demand ransoms between 1,2 and 5 Bitcoins. DEV-0530 is believed to have links to several other ransomware groups, including Plutonium alias DarkSeoul or Andariel, a North Korean-based sub-group operating under the Lazarus umbrella (aka Zinc or Hidden Cobra).

While it began targeting small businesses since September 2021, four different variants of the H0lyGh0st ransomware were churned out between June 2021 and May 2022 to target Windows systems. These include BTLC_C exe, HolyRS.exe, HolyLock.exe, and BLTC.

BTLC _C.exe dubbed SiennaPurple is written in C++, while the other three versions (codenamed SiennaBlue are programmed in Go, indicating an attempt to develop cross-platform malware.

“Along with their H0lyGh0st payload, DEV-0530 maintains an .onion site that the group uses to interact with their victims. The group’s standard methodology is to encrypt all files on the target device and use the file extension. h0lyenc, send the victim a sample of the files as proof, and then demand payment in Bitcoin in exchange for restoring access to the files,” the researchers said.

The sources for this piece include an article in TheHackerNews.

SUBSCRIBE NOW

Related articles

North Korean Job Scam Targeting IT Job Seekers

North Korea’s Lazarus advanced persistent threat (APT) group has launched a sophisticated campaign, “Operation 99,” targeting freelance software...

Hackers Exploit FastHTTP in High-Speed Microsoft 365 Attacks

Threat actors are employing the FastHTTP Go library to launch high-speed brute-force password attacks on Microsoft 365 accounts...

YouTubers Targeted As Cyberattackers Hide Infostealers in YouTube Comments, Google Search Results

Attackers have found a new way to infect people seeking pirated or cracked software: planting malicious download links...

New macOS Malware Exploits Apple’s Security Features to Stay Hidden and Steal User Data

A newly discovered variant of the Banshee macOS Stealer malware is putting 100 million Apple users at risk...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways