hellogookie logo

hellogookie

1 incidentes 0 paises 0 sectores ransomware UA Ultimo: 2026-06-25
Aliases: FiveHands, HelloKitty, Gookee, Kapuchin0
Ver en IntelTracker → APTTrail →
Hellogookie is a ransomware group that emerged in April 2024 as a rebrand of the notorious HelloKitty ransomware operation. Its creator, known by the aliases Gookee, Kapuchin0, and Guki, shut down the original HelloKitty operation in October 2023, subsequently launching HelloGookie to continue ransomware activities with updated tactics. The group's primary motivation is financial extortion, employing double and triple extortion tactics. A defining characteristic of HelloGookie is its explicit attempt to avoid direct competition and potentially collaborate with other major ransomware groups, such as LockBit, while also openly recruiting individuals for voice phishing operations. HelloGookie operates under the direct control of its developer, who has a history of collaborating with other ransomware groups like Yanluowang, and is assessed with moderate confidence to be of Ukrainian origin.
Tecnicas MITRE
T1071.001, T1018, T1059.003, T1486, T1490

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises objetivo (SOCRadar)

United Arab EmiratesAustraliaBelgiumBrazilGermanySpainFranceUnited KingdomItalyJapan

Sectores objetivo (SOCRadar)

Other Information ServicesSoftware PublishersHospitalsAir TransportationManufacturingPublic AdministrationEducational ServicesEnergy & Utilities InsuranceEducational Support Services

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com