SiennaPurple is a ransomware strain attributed to North Korean threat actors, tracked by Microsoft's Threat Intelligence Center as DEV-0530. Unlike opportunistic ransomware that casts a wide net, SiennaPurple has been deployed in targeted attacks against small-to-medium businesses, with attackers often combining file encryption with direct extortion demands. If you've received a ransom note referencing "HolyGh0st" or "H0lyGh0st," or if your files suddenly sport unfamiliar extensions and won't open, you may be dealing with this specific threat.
Threat Profile
| Threat Name | SiennaPurple (aka HolyLocker, H0lyGh0st) |
| Threat Type | Ransomware |
| Attributed Actor | DEV-0530 (North Korean nexus) |
| Target Platform | Windows (PE executable) |
| File Type | Windows PE executable |
| First Observed | Early 2022 |
| Distribution Method | Targeted intrusion, remote desktop compromise, phishing with malicious attachments |
| Encryption Strength | Strong asymmetric encryption (observed RSA-2048 or similar) |
| Common Aliases (AV) | HolyLocker, H0lyGh0st, SiennaPurple |
| Ransom Demand Range | Varies by target (typically $1,200–$5,000 in cryptocurrency) |
| Data Exfiltration | Observed in some campaigns (double-extortion tactics) |
| Last Updated (Malpedia) | 2026-09-24 |
How It Spreads
SiennaPurple is not distributed through mass spam campaigns or exploit kits the way many consumer-grade ransomware families are. Instead, DEV-0530 operators gain initial access through deliberate reconnaissance and social engineering. They identify targets—often smaller organizations without dedicated IT security teams—then exploit weak credentials, unpatched vulnerabilities, or human trust to plant the ransomware payload manually.
Once inside a network, the attackers may spend days or weeks conducting reconnaissance, elevating privileges, and identifying high-value files before deploying the encryption routine. This hands-on-keyboard approach makes SiennaPurple infections less common than families like WannaCry or LockBit, but far more damaging when they occur.
Common distribution vectors include:
- Brute-force attacks on Remote Desktop Protocol (RDP): Open RDP ports with weak or default passwords are frequent entry points.
- Phishing emails with malicious attachments: Specially crafted Office documents or PDFs that exploit macro vulnerabilities or social-engineer victims into enabling content.
- Exploitation of unpatched software: Known CVEs in VPN appliances, web servers, or CMS platforms that allow initial foothold.
- Credential theft via info-stealers: Attackers may deploy separate malware to harvest credentials before introducing SiennaPurple.
- Supply-chain or third-party compromise: Gaining access through a trusted vendor's weaker security posture.
What It Does On Your Machine
After execution, SiennaPurple typically performs a brief system survey to identify the most valuable files—documents, spreadsheets, databases, images, and backups. It prioritizes user data directories and network shares, avoiding system files necessary for Windows to boot (a calculated move that ensures victims can still see the ransom note). The malware then begins encrypting files using strong asymmetric cryptography, appending a custom extension or renaming files entirely. Some variants drop multiple ransom notes in affected directories, often named FOR_DECRYPT.html or H0lyGh0st_READ_ME.txt.
Unlike older ransomware that might encrypt indiscriminately, SiennaPurple is selective and efficient. The encryption process can complete in under an hour on a typical desktop with a moderate number of files, though larger file servers may take longer. The malware often disables Volume Shadow Copy Service to prevent easy restoration from Windows' built-in recovery snapshots, and in some observed cases, it attempts to delete backup files from external drives or cloud-sync folders.
The ransom note directs victims to a Tor-based payment portal or provides a direct contact method (sometimes a Telegram handle or ProtonMail address). Demands are negotiable, with operators sometimes offering "proof of decryption" for a single file. Microsoft's analysis indicates DEV-0530 has also engaged in data exfiltration prior to encryption—threatening to publish stolen files if payment is not made, a tactic known as double extortion.
It's worth noting that not every sample behaves identically—DEV-0530 has iterated on the malware over time, and some variants exhibit more sophisticated evasion or lateral movement capabilities than others.
Manual Removal — Step by Step
Isolate the Infected System Immediately
Disconnect the computer from all networks—unplug Ethernet cables and disable Wi-Fi. If the machine is part of a domain, alert your IT staff before proceeding. Remove any USB drives, external hard drives, or other peripherals. The goal is to prevent SiennaPurple from encrypting additional devices or network shares.
Boot Into Safe Mode With Networking
Restart the computer and press F8 (or Shift+F8 on newer systems) before Windows loads. Select "Safe Mode with Networking" from the boot menu. This limits which drivers and services load, making it harder for the ransomware to interfere with cleanup. If you cannot access Safe Mode, you may need to use a bootable recovery USB.
Identify and Terminate Malicious Processes
Open Task Manager (Ctrl+Shift+Esc) and look for unfamiliar processes, especially those running from C:\ProgramData, C:\Users\Public, or temp directories. Common process names include hgst.exe or random alphanumeric strings. Right-click and select "End Task," then note the file location for later deletion.
Remove Persistence Entries From the Registry
Press Win+R, type regedit, and press Enter. Navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run. Look for entries with unfamiliar names (e.g., "H0lyGh0st") pointing to executables in unusual locations. Right-click and delete these entries. Also check RunOnce keys in the same locations.
Delete the Malware Executable and Associated Files
Using File Explorer, navigate to the locations you noted in Step 3. Delete the malicious executable (you may need to take ownership of the file if permissions block you). Also remove any ransom notes (FOR_DECRYPT.html, H0lyGh0st_READ_ME.txt) and any suspicious DLLs or scripts in the same directories. Empty the Recycle Bin afterward.
Run a Full System Scan With Updated Antivirus
If you don't have reputable antivirus software installed, download one in Safe Mode (Windows Defender is acceptable if fully updated; Malwarebytes or Bitdefender are stronger choices). Update definitions, then run a complete system scan. Quarantine or delete anything flagged. Reboot and scan again in normal mode to confirm the threat is gone.
Attempt File Recovery (No Guarantees)
Check if Windows' Previous Versions feature has any pre-encryption snapshots (right-click an encrypted folder > Properties > Previous Versions). If SiennaPurple deleted shadow copies, third-party recovery tools like Recuva or PhotoRec may recover some files from unallocated disk space, but success rates are low with modern ransomware. Do not pay the ransom—there is no guarantee you'll receive a working decryption key, and payment funds criminal operations.
Restore From Clean Backups
If you maintain offline or cloud backups that pre-date the infection, this is the most reliable recovery path. Verify the backup integrity before restoring, and ensure the ransomware is completely removed from the system first. After restoration, change all passwords—especially for accounts that may have been compromised during the initial intrusion.
Harden Remote Access and Credentials
If RDP was the entry vector, disable it entirely or restrict access by IP whitelist and enforce multi-factor authentication. Change all administrative passwords to strong, unique passphrases (20+ characters). Audit user accounts for unexpected additions or privilege escalations made by the attacker during their dwell time.
Monitor for Residual Indicators
For the next two weeks, watch for unusual network traffic, unexpected reboots, or new files appearing in C:\ProgramData or AppData. Review Windows Event Logs (Event Viewer > Windows Logs > Security) for failed login attempts or privilege-use auditing anomalies. If you see anything suspicious, re-scan immediately.
Prevention
- Implement a robust, offline backup strategy. Maintain at least one backup copy on a device that is disconnected from the network after each backup cycle. Cloud backups are useful but should be supplemented with a local, air-gapped solution that ransomware cannot reach.
- Disable or secure Remote Desktop Protocol. If RDP must be enabled, place it behind a VPN, enforce multi-factor authentication, and use account lockout policies to thwart brute-force attacks. Monitor RDP logs for failed login attempts from unfamiliar IPs.
- Keep all software patched and current. Enable automatic updates for Windows, Office, and any third-party applications. Prioritize patching known vulnerabilities in VPN appliances, web servers, and content management systems—these are common entry points for targeted attackers.
- Deploy reputable endpoint protection with behavioral monitoring. Modern antivirus solutions that use heuristics and machine learning can detect ransomware behavior (mass file encryption, shadow copy deletion) even if the specific variant is unknown. Configure real-time protection and schedule regular full scans.
- Educate users about phishing and social engineering. Conduct periodic training on recognizing suspicious emails, verifying sender identities, and avoiding macros in unsolicited Office documents. A single lapse in judgment can grant attackers the foothold they need.
- Segment your network and limit privilege escalation. Use separate VLANs for critical servers and restrict administrative access to a small number of hardened accounts. Employ the principle of least privilege—users should only have the permissions necessary for their specific roles.
- Enable and configure Windows Defender Exploit Guard or equivalent. Features like Controlled Folder Access can prevent unauthorized applications from modifying files in protected directories, adding a layer of defense against ransomware encryption.
- Conduct regular security audits and penetration testing. For businesses, periodic vulnerability assessments can identify weaknesses before attackers do. Even small organizations benefit from annual third-party reviews of their security posture.
Bring It In
Ransomware infections are among the most stressful computer emergencies our customers face, and SiennaPurple's targeted nature makes it particularly devastating. While the manual steps above may help tech-savvy users contain the damage, the truth is that complete remediation—and especially file recovery—often requires forensic tools, decryption research, and experience with post-infection hardening that most home users and small businesses simply don't have in-house.
At Computer Repair Roswell, we've handled ransomware cases ranging from opportunistic attacks to sophisticated intrusions like SiennaPurple. We'll assess the extent of encryption, check for data exfiltration indicators, and advise you honestly on recovery options—including whether your backups are viable or if third-party decryption tools exist for your specific variant. We're located at 1750 Woodstock Rd, Roswell, GA, open Monday through Friday 10 AM to 6 PM, and Saturday 10 AM to 4 PM. Call us at (770) 679-9844 or stop by. Don't let a North Korean ransomware gang hold your files hostage—let's take back control together.