The HolyGhost ransomware spread by the APT group known as Dark Seoul also created a task using schtasks.exe. | the attackers used a privileged account to run various files on the system and to run a malicious file known as HolyGhost Ransomware.
HolyGhost
HolyGhost is a Windows ransomware family associated with North Korean threat activity and publicly linked to operations attributed to Dark Seoul.
Profile source: Mallory opens in a new tabHolyGhost
Family profile
HolyGhost is a Windows ransomware family associated with North Korean threat activity and publicly linked to operations attributed to Dark Seoul. It has been observed in financially motivated intrusions, including attacks against government environments, where operators used compromised or privileged accounts, scheduled tasks, and Windows services to deploy the ransomware across multiple systems. In documented intrusions, HolyGhost was part of broader post-compromise activity that also included disabling Microsoft Defender protections, credential dumping, network scanning, tool transfer with PowerShell, and deployment of additional monetization tooling such as cryptominers.
HolyGhost encrypts victim files using AES and appends a distinctive encrypted-file extension. It has been reported to retrieve a public key from attacker-controlled infrastructure as part of its encryption workflow. Operationally, it has been observed creating scheduled-task persistence or execution mechanisms running at high privilege, including recurring execution as SYSTEM. The malware is part of a wider pattern of North Korean ransomware use alongside other families such as Maui and PLAY, reflecting the overlap between state-linked intrusion tradecraft and revenue-generating cybercrime.
Observed victimology includes government-sector targets, and the surrounding intrusion activity indicates use in enterprise-wide compromises rather than opportunistic single-host infections. High-confidence reporting supports HolyGhost as a ransomware payload used after successful access and lateral movement within Windows networks.
Capabilities
- Credential Theft
- Defense Evasion
- Extortion
- Persistence
- Privilege Escalation
- Scanning
Operational record
Reported operators
Threat actors
2 named in public reportingNorth Korean threat actors have previously been linked to other ransomware strains such as HolyGhost, PLAY, Maui, Qilin...
Exploited software
Vulnerabilities linked to HolyGhost
1 CVEsMITRE ATT&CK