Cyber Resilience

Threat actor · all actors

Storm-0530MISP-47945864 state

🇰🇵 KP

aka Storm-0530, DEV-0530, H0lyGh0st

Last updated: 2026-08-22

11attributed CVEs
0ATT&CK techniques
31.9IDF score (tooling uniqueness)
0exclusive CVEs
2018–2022years active

About this actor

H0lyGh0st is a North Korean threat actor that has been active since June 2021. They are responsible for developing and deploying the H0lyGh0st ransomware, which targets small-to-medium businesses in various sectors. The group employs "double extortion" tactics, encrypting data and threatening to publish it if the ransom is not paid. There are connections between H0lyGh0st and the PLUTONIUM APT group, indicating a possible affiliation.

Names & naming systems

Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.

Microsoftweather-system names

Storm-0530

Unclassifiedno scheme matched

DEV-0530H0lyGh0st

How we know this

Data origin
MISP threat-actor galaxy Imported from the open-source MISP threat-actor galaxy.
Techniques
No ATT&CK techniques mapped.
Named victims
None on file.

Thin data: No ATT&CK techniques are mapped yet — the behavioural profile is empty.

See how actor data is built for the full pipeline.

Activity timeline

Profile

CVERiskCVSSEPSSPublishedProducts
CVE-2021-3018 9.99.80.79332021-01-05see CVE
CVE-2021-45837 9.99.80.81082022-04-25see CVE
CVE-2021-44142 9.18.80.74042022-02-21see CVE
CVE-2022-22005 7.78.80.17212022-02-09see CVE
CVE-2019-15637 7.48.10.22732019-08-26see CVE
CVE-2022-24665 7.49.90.02602022-02-16see CVE
CVE-2022-24663 7.39.90.02102022-02-16see CVE
CVE-2022-24664 7.39.90.01652022-02-16see CVE
CVE-2021-40684 7.19.10.01242021-09-22see CVE
CVE-2022-24785 6.57.50.05662022-04-04see CVE
CVE-2017-4946 5.97.80.00512018-01-05see CVE

No techniques attributed.

Co-occurring actors

Similar actors

Overlapping CVEs

Active in same years