it-22-201-001 (1)

10658740083?profile=RESIZE_400xA group of actors originating from North Korea that Microsoft Threat Intelligence Center (MSTIC) tracks as DEV-0530 has been developing and using ransomware in attacks since June 2021.  This group, which calls itself H0lyGh0st, utilizes a ransomware payload with the same name for its campaigns and has successfully compromised small businesses in multiple countries as early as September 2021.

Link to full MS report: IR-22-201-001_H0lyGh0st.pdf