Hellcat, also known as HELLCAT, Hellcat Ransomware Group, and GOLD PUMPKIN, is a financially motivated cybercriminal operation that emerged in 2024. It operates within the ransomware-as-a-service ecosystem and is associated with ransomware, data theft, and extortion. Its pressure tactics include threats to publish stolen information, public shaming, and humiliation. The operation maintains a data-leak site and has personnel links to the BreachForums community. A recurring initial-access method is the use of corporate credentials harvested by infostealer malware to compromise Atlassian Jira environments. Operators extract project records, source code, internal documents, and employee or partner information from these systems. In the November 2024 Schneider Electric breach, an operator accessed Jira using exposed credentials and scraped approximately 400,000 rows of user data through the MiniOrange REST API. Other linked incidents include the January 2025 compromise of Telefónica's internal Jira environment, the March 2025 Jaguar Land Rover data breach, and a compromise of Ascom's technical ticketing system. These incidents demonstrate targeting of industrial technology, automotive, telecommunications, and communications-technology organizations. Hellcat's ecosystem includes distinct access-brokering, intrusion, and administrative roles. Rey, also known as Hikki-Chan and ReyXBF, was a member and administrator of its data-leak site. Miyako, also known as mommy, operated as an associated initial access broker, supplying compromised enterprise footholds rather than directly deploying ransomware. Personnel connections with other cybercriminal brands do not establish that those groups are aliases of Hellcat.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware group mentioned as background to Khader's previous activities. He reportedly operated its data-leak site; the article does not connect Hellcat to the current FBI breach or investigation.
Mentioned in background on Rey's earlier activities. Rey reportedly claimed membership in HellCat but said he independently carried out the breach of Orange's Romanian subsidiary. The article therefore does not establish that this attack was a HellCat operation.
A ransomware operation associated with the arrested suspect's earlier activities. The content links his participation in HellCat to the January 2025 breach of Telefónica's internal Jira system and theft of approximately 2.3 GB of data.
A ransomware group mentioned as background to Rey's previous administration of its data-leak website.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.