holyghost Unknown
First seen:
-
0
Total Victims
0
Victims (30d)
Details
HolyGhost (tracked by Microsoft as DEV-0530) is a North Korean state-linked ransomware group active since June 2021, associated with the Andariel threat group, targeting small to mid-sized businesses in financial services, manufacturing, education, and entertainment globally.
Leak Site
Onion URL:
http://matmq3z3hiovia3voe2tix2x54sghc3tszj74xgdy4tqtypoycszqzqd.onion
Metadata
Slug:
holyghost
Created: 14/01/2026 08:19
Updated: 28/06/2026 16:02