Skip to content

holyghost

Inactive

0 tracked victims

About

Aggregated threat-intel description

HolyGhost (tracked by Microsoft as DEV-0530) is a North Korean state-linked ransomware group active since June 2021, associated with the Andariel threat group, targeting small to mid-sized businesses in financial services, manufacturing, education, and entertainment globally.

Recent victims

View all →
No recent victims.

All ransomware groups · Dark web intelligence