SiennaPurple is a ransomware strain attributed to North Korean threat actors, tracked by Microsoft's Threat Intelligence Center as DEV-0530. Unlike opportunistic ransomware that casts a wide net, SiennaPurple has been deployed in targeted attacks against small-to-medium businesses, with attackers often combining file encryption with direct extortion demands. If you've received a ransom note referencing "HolyGh0st" or "H0lyGh0st," or if your files suddenly sport unfamiliar extensions and won't open, you may be dealing with this specific threat.

SiennaPurple — cybersecurity illustration
Photo by Ann H on Pexels
Already Infected? Act Now: If you suspect SiennaPurple is active on your machine, immediately power down the computer to prevent further encryption. Do NOT attempt to delete files or pay any ransom before consulting a professional. Disconnect any external drives or network storage. Call Computer Repair Roswell at (770) 679-9844 for emergency assessment—we can evaluate the extent of encryption and advise on recovery options during business hours.

Threat Profile

Threat NameSiennaPurple (aka HolyLocker, H0lyGh0st)
Threat TypeRansomware
Attributed ActorDEV-0530 (North Korean nexus)
Target PlatformWindows (PE executable)
File TypeWindows PE executable
First ObservedEarly 2022
Distribution MethodTargeted intrusion, remote desktop compromise, phishing with malicious attachments
Encryption StrengthStrong asymmetric encryption (observed RSA-2048 or similar)
Common Aliases (AV)HolyLocker, H0lyGh0st, SiennaPurple
Ransom Demand RangeVaries by target (typically $1,200–$5,000 in cryptocurrency)
Data ExfiltrationObserved in some campaigns (double-extortion tactics)
Last Updated (Malpedia)2026-09-24

How It Spreads

SiennaPurple is not distributed through mass spam campaigns or exploit kits the way many consumer-grade ransomware families are. Instead, DEV-0530 operators gain initial access through deliberate reconnaissance and social engineering. They identify targets—often smaller organizations without dedicated IT security teams—then exploit weak credentials, unpatched vulnerabilities, or human trust to plant the ransomware payload manually.

Once inside a network, the attackers may spend days or weeks conducting reconnaissance, elevating privileges, and identifying high-value files before deploying the encryption routine. This hands-on-keyboard approach makes SiennaPurple infections less common than families like WannaCry or LockBit, but far more damaging when they occur.

Common distribution vectors include:

  • Brute-force attacks on Remote Desktop Protocol (RDP): Open RDP ports with weak or default passwords are frequent entry points.
  • Phishing emails with malicious attachments: Specially crafted Office documents or PDFs that exploit macro vulnerabilities or social-engineer victims into enabling content.
  • Exploitation of unpatched software: Known CVEs in VPN appliances, web servers, or CMS platforms that allow initial foothold.
  • Credential theft via info-stealers: Attackers may deploy separate malware to harvest credentials before introducing SiennaPurple.
  • Supply-chain or third-party compromise: Gaining access through a trusted vendor's weaker security posture.

What It Does On Your Machine

After execution, SiennaPurple typically performs a brief system survey to identify the most valuable files—documents, spreadsheets, databases, images, and backups. It prioritizes user data directories and network shares, avoiding system files necessary for Windows to boot (a calculated move that ensures victims can still see the ransom note). The malware then begins encrypting files using strong asymmetric cryptography, appending a custom extension or renaming files entirely. Some variants drop multiple ransom notes in affected directories, often named FOR_DECRYPT.html or H0lyGh0st_READ_ME.txt.

Unlike older ransomware that might encrypt indiscriminately, SiennaPurple is selective and efficient. The encryption process can complete in under an hour on a typical desktop with a moderate number of files, though larger file servers may take longer. The malware often disables Volume Shadow Copy Service to prevent easy restoration from Windows' built-in recovery snapshots, and in some observed cases, it attempts to delete backup files from external drives or cloud-sync folders.

The ransom note directs victims to a Tor-based payment portal or provides a direct contact method (sometimes a Telegram handle or ProtonMail address). Demands are negotiable, with operators sometimes offering "proof of decryption" for a single file. Microsoft's analysis indicates DEV-0530 has also engaged in data exfiltration prior to encryption—threatening to publish stolen files if payment is not made, a tactic known as double extortion.

# Observed indicators (sandbox environment) C:\Users\[Username]\Documents\*.locked — Files renamed with .locked extension C:\Users\Public\FOR_DECRYPT.html — Ransom note dropped in Public folder C:\ProgramData\hgst.exe — Persistent executable (observed in sandbox) # Registry modification (observed) HKCU\Software\Microsoft\Windows\CurrentVersion\Run "H0lyGh0st" = "C:\ProgramData\hgst.exe" — Persistence mechanism # Process activity (observed) vssadmin delete shadows /all /quiet — Deletes shadow copies wmic shadowcopy delete — Secondary deletion attempt # Network contact (observed in some samples) Connection to Tor relay nodes — C2 communication via Tor

It's worth noting that not every sample behaves identically—DEV-0530 has iterated on the malware over time, and some variants exhibit more sophisticated evasion or lateral movement capabilities than others.

Manual Removal — Step by Step

01

Isolate the Infected System Immediately

Disconnect the computer from all networks—unplug Ethernet cables and disable Wi-Fi. If the machine is part of a domain, alert your IT staff before proceeding. Remove any USB drives, external hard drives, or other peripherals. The goal is to prevent SiennaPurple from encrypting additional devices or network shares.

02

Boot Into Safe Mode With Networking

Restart the computer and press F8 (or Shift+F8 on newer systems) before Windows loads. Select "Safe Mode with Networking" from the boot menu. This limits which drivers and services load, making it harder for the ransomware to interfere with cleanup. If you cannot access Safe Mode, you may need to use a bootable recovery USB.

03

Identify and Terminate Malicious Processes

Open Task Manager (Ctrl+Shift+Esc) and look for unfamiliar processes, especially those running from C:\ProgramData, C:\Users\Public, or temp directories. Common process names include hgst.exe or random alphanumeric strings. Right-click and select "End Task," then note the file location for later deletion.

04

Remove Persistence Entries From the Registry

Press Win+R, type regedit, and press Enter. Navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run. Look for entries with unfamiliar names (e.g., "H0lyGh0st") pointing to executables in unusual locations. Right-click and delete these entries. Also check RunOnce keys in the same locations.

05

Delete the Malware Executable and Associated Files

Using File Explorer, navigate to the locations you noted in Step 3. Delete the malicious executable (you may need to take ownership of the file if permissions block you). Also remove any ransom notes (FOR_DECRYPT.html, H0lyGh0st_READ_ME.txt) and any suspicious DLLs or scripts in the same directories. Empty the Recycle Bin afterward.

06

Run a Full System Scan With Updated Antivirus

If you don't have reputable antivirus software installed, download one in Safe Mode (Windows Defender is acceptable if fully updated; Malwarebytes or Bitdefender are stronger choices). Update definitions, then run a complete system scan. Quarantine or delete anything flagged. Reboot and scan again in normal mode to confirm the threat is gone.

07

Attempt File Recovery (No Guarantees)

Check if Windows' Previous Versions feature has any pre-encryption snapshots (right-click an encrypted folder > Properties > Previous Versions). If SiennaPurple deleted shadow copies, third-party recovery tools like Recuva or PhotoRec may recover some files from unallocated disk space, but success rates are low with modern ransomware. Do not pay the ransom—there is no guarantee you'll receive a working decryption key, and payment funds criminal operations.

08

Restore From Clean Backups

If you maintain offline or cloud backups that pre-date the infection, this is the most reliable recovery path. Verify the backup integrity before restoring, and ensure the ransomware is completely removed from the system first. After restoration, change all passwords—especially for accounts that may have been compromised during the initial intrusion.

09

Harden Remote Access and Credentials

If RDP was the entry vector, disable it entirely or restrict access by IP whitelist and enforce multi-factor authentication. Change all administrative passwords to strong, unique passphrases (20+ characters). Audit user accounts for unexpected additions or privilege escalations made by the attacker during their dwell time.

10

Monitor for Residual Indicators

For the next two weeks, watch for unusual network traffic, unexpected reboots, or new files appearing in C:\ProgramData or AppData. Review Windows Event Logs (Event Viewer > Windows Logs > Security) for failed login attempts or privilege-use auditing anomalies. If you see anything suspicious, re-scan immediately.

Prevention

  1. Implement a robust, offline backup strategy. Maintain at least one backup copy on a device that is disconnected from the network after each backup cycle. Cloud backups are useful but should be supplemented with a local, air-gapped solution that ransomware cannot reach.
  2. Disable or secure Remote Desktop Protocol. If RDP must be enabled, place it behind a VPN, enforce multi-factor authentication, and use account lockout policies to thwart brute-force attacks. Monitor RDP logs for failed login attempts from unfamiliar IPs.
  3. Keep all software patched and current. Enable automatic updates for Windows, Office, and any third-party applications. Prioritize patching known vulnerabilities in VPN appliances, web servers, and content management systems—these are common entry points for targeted attackers.
  4. Deploy reputable endpoint protection with behavioral monitoring. Modern antivirus solutions that use heuristics and machine learning can detect ransomware behavior (mass file encryption, shadow copy deletion) even if the specific variant is unknown. Configure real-time protection and schedule regular full scans.
  5. Educate users about phishing and social engineering. Conduct periodic training on recognizing suspicious emails, verifying sender identities, and avoiding macros in unsolicited Office documents. A single lapse in judgment can grant attackers the foothold they need.
  6. Segment your network and limit privilege escalation. Use separate VLANs for critical servers and restrict administrative access to a small number of hardened accounts. Employ the principle of least privilege—users should only have the permissions necessary for their specific roles.
  7. Enable and configure Windows Defender Exploit Guard or equivalent. Features like Controlled Folder Access can prevent unauthorized applications from modifying files in protected directories, adding a layer of defense against ransomware encryption.
  8. Conduct regular security audits and penetration testing. For businesses, periodic vulnerability assessments can identify weaknesses before attackers do. Even small organizations benefit from annual third-party reviews of their security posture.
Our 90-Day Warranty: When Computer Repair Roswell performs a complete malware removal—including SiennaPurple or any ransomware variant—we guarantee the infection is gone. If the same threat reappears within 90 days due to incomplete removal (not reinfection from unsafe behavior), we'll fix it again at no additional labor charge. That's our commitment to thoroughness.

Bring It In

Ransomware infections are among the most stressful computer emergencies our customers face, and SiennaPurple's targeted nature makes it particularly devastating. While the manual steps above may help tech-savvy users contain the damage, the truth is that complete remediation—and especially file recovery—often requires forensic tools, decryption research, and experience with post-infection hardening that most home users and small businesses simply don't have in-house.

At Computer Repair Roswell, we've handled ransomware cases ranging from opportunistic attacks to sophisticated intrusions like SiennaPurple. We'll assess the extent of encryption, check for data exfiltration indicators, and advise you honestly on recovery options—including whether your backups are viable or if third-party decryption tools exist for your specific variant. We're located at 1750 Woodstock Rd, Roswell, GA, open Monday through Friday 10 AM to 6 PM, and Saturday 10 AM to 4 PM. Call us at (770) 679-9844 or stop by. Don't let a North Korean ransomware gang hold your files hostage—let's take back control together.