holyghost Unknown

First seen: -
0
Total Victims
0
Victims (30d)
Details

HolyGhost (tracked by Microsoft as DEV-0530) is a North Korean state-linked ransomware group active since June 2021, associated with the Andariel threat group, targeting small to mid-sized businesses in financial services, manufacturing, education, and entertainment globally.

Leak Site

Onion URL: http://matmq3z3hiovia3voe2tix2x54sghc3tszj74xgdy4tqtypoycszqzqd.onion

Metadata

Slug: holyghost

Created: 14/01/2026 08:19

Updated: 28/06/2026 16:02