HolyGhostâs Bargain Basement Approach to Ransomware
ID: d498555a-6d54-5931-afea-57a0f10e0ae5
STIX ID: report--d498555a-6d54-5931-afea-57a0f10e0ae5
Feed Name: ReliaQuest Blog
HolyGhost is a North Korea-linked ransomware group that targets small and medium-sized enterprises with double-extortion operations and a poorly maintained data-leak site; the group charges unusually low ransoms and appears connected to DPRK APT activity (e.g., DarkSeoul/Lazarus). The report assesses operational challenges (infrastructure, talent, state revenue extraction) and likely continued SME-focused financially motivated activity, noting limited visibility into scale and few posted victims.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
