HelloKitty is a human-operated ransomware operation active since November 2020 that conducts enterprise intrusions involving data theft and file encryption. It is also referred to as Hello Kitty, HelloKity, Kitty, and has been associated in reporting with DeathRansom and FiveHands; later reporting has described Kraken as emerging from remnants of the HelloKitty operation. HelloKitty is best known for high-profile attacks against corporate victims, including the February 2021 compromise of CD Projekt Red, and for later expanding to Linux encryptors aimed at VMware ESXi environments. The operation has used double extortion, stealing victim data before encryption and threatening to leak or sell it if payment is refused. Victim communications have used Tor-based negotiation infrastructure, and the group has been linked to extortion activity against large organizations in multiple countries. Reported victims and targeting evidence include organizations in Poland, Brazil, and the United States, with activity against video game developers and energy-sector entities. Technically, HelloKitty has been described as a ransomware family written initially in C++ with later Go-based variants. Variants have used multiple encryption schemes, including AES with RSA or NTRU, and Linux variants using OpenSSL/ECDH-based approaches have been reported. The malware has been observed deleting volume shadow copies to inhibit recovery, terminating large numbers of processes and services, and dropping characteristic ransom notes. By mid-2021, HelloKitty operators had developed Linux/ESXi encryptors, aligning with the broader ransomware trend of targeting virtualized enterprise infrastructure to maximize impact by encrypting many hosted systems at once. Initial access and propagation reporting around HelloKitty includes exploitation of vulnerable edge devices, especially SonicWall SMA/SRA appliances, as well as broader enterprise intrusion methods commonly associated with human-operated ransomware. The group has also been linked in technical reporting to attacks leveraging compromised remote access pathways and to later ecosystem relationships or code lineage involving Vice Society, Boombye, Kitty Go, Kitty Linux, and possibly Abyss Locker, although some of these relationships may reflect source-code reuse or spin-offs rather than a single continuous operator set. Overall, HelloKitty is a financially motivated ransomware threat actor focused on corporate network compromise, data exfiltration, encryption, and extortion, with notable adaptation to Linux and ESXi targets and a legacy that appears to have influenced multiple later ransomware strains and successor operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as a strong ransomware brand admired for recognition and marketing value.
Referenced as a ransomware group that some former Conti members allegedly joined after Conti’s retirement; described here as no longer active.
HelloKitty is a defunct or diminished ransomware cartel, with remnants linked to the emergence of the Kraken ransomware operation.
Referenced as a ransomware cartel whose remnants are associated with the emergence of the Kraken group.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.