hellokitty logo

hellokitty

1 incidentes 0 paises 0 sectores ransomware UA Ultimo: 2026-06-25
Aliases: hellokitty, KittyCrypt, HelloGookie, FiveHands
Ver en IntelTracker → APTTrail →
HelloKitty, also known by the alias FiveHands, is a ransomware operation that first emerged in late 2020, with its initial samples observed in October. The group is characterized by its rapid adaptation of new tactics, techniques, and procedures, notably deploying both Windows and Linux variants of its ransomware, including a version targeting VMware ESXi environments. Initially, the group was assessed with moderate confidence to be of Ukrainian origin, though recent activity suggests an evolving geographic footprint with samples uploaded from Chinese IP addresses. Its primary motivation is financial gain through data encryption and extortion, employing double extortion tactics by exfiltrating data prior to encryption and threatening its release or sale. A distinguishing behavior is its customization of ransom notes, often addressing victims by name, and its use of a unique mutex, "HelloKittyMutex," upon execution. The group is also known for sometimes opening a shell terminal to displ
Malware asociado
TigerRAT, NukeSped, Andariel, TigerRAT
Tecnicas MITRE
T1568, T1057, T1106, T1083, T1078, T1189
CVEs relacionadas
CVE-2023-46604, CVE-2023-22518, CVE-2021-20023, CVE-2021-20022, CVE-2021-20021, CVE-2021-20016

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises objetivo (SOCRadar)

United Arab EmiratesArgentinaAustraliaBelgiumBrazilChinaGermanySpainFranceUnited Kingdom

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesSoftware PublishersHospitalsAir TransportationManufacturingConstructionElectrical Equipment, Appliance, and Component ManufacturingPublic Administration

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com