Recommended Free Tools
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
On July 14, 2022, Microsoft reported that a North Korea-origin threat cluster it then called DEV-0530 had targeted small and midsize businesses (SMBs) with H0lyGh0st ransomware. Microsoft later renamed the cluster Storm-0530. Its report described victims in several sectors, a file-theft-and-encryption extortion pattern, and malware variants identified during 2021 and 2022; it is a historical account, not a measure of the ransomware threat landscape in 2026.
DEV-0530 became Storm-0530; H0lyGh0st is the ransomware name
Microsoft’s 2022 report tracked the North Korea-origin activity cluster as DEV-0530 and said the group called itself H0lyGh0st and used ransomware bearing that name. In an April 2023 update, Microsoft said it had begun tracking the cluster as Storm-0530. Microsoft’s January 2024 profile confirms that Storm-0530 was formerly DEV-0530. Microsoft’s Storm-0530 profile provides the later naming.
These labels refer to related but distinct things: Storm-0530 is Microsoft’s name for the threat actor cluster; H0lyGh0st is the group’s self-name and the name of its ransomware.
How the reported extortion worked
Microsoft said the group had developed and used ransomware since June 2021 and had compromised small businesses in multiple countries as early as September 2021. Its reported sequence combined data theft with encryption:
#1 Best Overall
- World’s First 6TB 2.5” Portable Hard Drive
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- The attackers exfiltrated victim files.
- They encrypted files and changed their names by appending
.h0lyenc. - They left a ransom note, including at
C:FOR_DECRYPT.html, and provided sample victim files as proof of access. - They demanded payment in Bitcoin in exchange for restoring access, while threatening to publish stolen data or send it to victims’ customers.
MSTIC reported initial demands of 1.2 to 5 Bitcoin in its 2022 account. It said the attackers were often willing to negotiate, sometimes reducing the initial demand to less than one-third. Those are historical figures, not current estimates of Bitcoin value or a prediction of what a victim would be asked to pay. Microsoft said that, as of early July 2022, it saw no successful extortion in the wallet transactions it reviewed. That limited observation does not establish that no victim paid by another route. The group also maintained an onion site for communicating with victims. Microsoft’s July 2022 report includes its incident details, indicators, and hunting queries; the listed indicators are not exhaustive.
Victims and the suspected access route
Microsoft said the victims it reviewed were primarily SMBs in manufacturing, banking, schools, and event and meeting planning. It assessed that HolyRS.exe had been used against multiple targets in November 2021.
Rank #2
- Slim durable design to help take your important files with you
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
Microsoft suspected that attackers might have exploited vulnerabilities in public-facing applications or content-management systems to gain access. It named CVE-2022-26352, a remote-code-execution vulnerability in DotCMS, as an example of a vulnerability that could have been used. This was a suspected route, not a confirmed universal entry method: Microsoft said it had not observed zero-day exploitation in these attacks.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Microsoft’s historical malware classifications
For samples gathered between June 2021 and May 2022, the Microsoft Threat Intelligence Center (MSTIC) classified the malware into two families, SiennaPurple and SiennaBlue. Its report identified four samples and described their languages and classifications as follows:
Rank #3
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
| Sample | Microsoft’s reported details |
|---|---|
| BTLC_C.exe | C++ executable; classified as SiennaPurple. |
| HolyRS.exe | Go Windows executable; classified as SiennaBlue. |
| HolyLock.exe | Go Windows executable; classified as SiennaBlue. |
| BLTC.exe | Go Windows executable; classified as SiennaBlue. |
MSTIC clustered the samples using code similarities, command-and-control infrastructure, and ransom-note text. Microsoft said Defender Antivirus detected and blocked known variants at the time of the report; that historical statement is not a guarantee about current protection or detection coverage.
Attribution and motive were not settled
Microsoft reported communications between DEV-0530 and accounts associated with PLUTONIUM, infrastructure overlap, and use of tools it attributed exclusively to PLUTONIUM. The 2022 report also used the PLUTONIUM aliases DarkSeoul and Andariel; Microsoft’s later profile calls that group Onyx Sleet, formerly PLUTONIUM. Microsoft nevertheless said differences in operational tempo, targeting, and tradecraft suggested they were distinct groups. The reported connections do not establish that DEV-0530 and PLUTONIUM were the same group.
Rank #4
- THREAT DETECTION – Stay one step ahead. Suspicious links, risky sites, viruses, and scams, caught automatically before they reach you.
- PERSONAL INFO PROTECTION – Keep your personal info safer. Identity monitoring watches for your exposed info and tells you what to do about it.
- SECURE CONNECTIONS – Just a few easy clicks, and we'll automatically protect your info on public Wi‑Fi, every time you connect.
- GUIDED ACTION – Know what matters and what to do next. Clear alerts and simple guidance make it easy to take action.
- MORE THAN ANTIVIRUS – Scam protection, identity monitoring, VPN, web protection, and antivirus work together to protect you, all in one place.
Microsoft discussed more than one possible motive and said it could not be certain. State sponsorship intended to offset financial losses was one possibility; individuals with ties to PLUTONIUM tools or infrastructure acting for personal gain was another. Neither explanation was established as fact.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →What SMBs can take from the report
The most durable lesson is to plan for both data loss and recovery: the activity Microsoft described involved stealing files as well as encrypting them. Microsoft encouraged organizations to implement and frequently validate a backup and restore plan as part of broader protection against ransomware and extortion.
Quick Recap
Best Value
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
- Test restoration, not just backup creation. Keep recovery instructions and access available if ordinary business accounts or systems are compromised. A removable external drive can be one component, but it is not a complete resilience plan; Microsoft did not prescribe a specific product, capacity, or architecture.
- Strengthen sign-in protections. Use multifactor authentication (MFA), disable legacy authentication where it is not needed, and review accounts and permissions for unnecessary access.
- Harden cloud and identity systems. Review administrative access and monitor for suspicious sign-ins or changes, since a ransomware incident can involve more than endpoint files.
- Keep defenses current. Microsoft’s report named Defender for Business, Microsoft 365 Business Premium, and Defender controls as part of SMB security guidance. Product features and packaging can change, so consult current Microsoft documentation for configuration details rather than relying on 2022 feature descriptions.
- Use threat indicators carefully. The report’s hashes, paths, and other indicators describe Microsoft’s investigation and are not a complete detection list. Security teams should consult the original report for exact indicators and hunting queries.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

