Kraken, also tracked as kraken_group, is a financially motivated, Russian-speaking ransomware operation linked to remnants of the HelloKitty ransomware cartel. Active in 2025, it operates a ransomware-as-a-service model and conducts big-game hunting against organizations internationally. Its double-extortion attacks combine data theft and encryption with threats to publish stolen information on leak sites. Listed victims span the United States, United Kingdom, Canada, Panama, Kuwait, and Denmark. Russian-language activity does not establish a country of origin. Kraken targets Windows, Linux, and VMware ESXi using platform-specific encryptors. Observed intrusions begin with exploitation of SMB vulnerabilities on internet-facing systems, followed by theft of administrative credentials and access through Remote Desktop Protocol. Operators deploy Cloudflared reverse tunnels to maintain access and support lateral movement, and use SSHFS to exfiltrate data through mounted remote filesystems. The ransomware benchmarks individual machines to select full or partial encryption according to their performance. Its Windows functionality covers Microsoft SQL Server data, reachable network shares, local drives, and Hyper-V virtual disks. Its virtualization-focused components enumerate and stop running virtual machines to unlock their disks for encryption. Before encryption, Kraken deletes shadow copies, clears the Recycle Bin, and stops backup services to impede recovery. Post-encryption cleanup removes logs, shell history, ransomware artifacts, and the cleanup script itself. The operation also employs anti-analysis techniques. At least one observed attack involved a $1 million ransom demand payable in Bitcoin. Kraken has launched a cybercrime forum named The Last Haven Board.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as another ransomware program in discussion about affiliate movement and options.
Darknet marketplace ecosystem using a hybrid clearnet/Tor architecture: clearnet CAPTCHA/login gateway domains broker sessions and route users to onion-hosted backend services. Observed behaviors include pre-authentication session binding via routing endpoints, Tor-aware routing cookies, distributed rotating gateway domains for redundancy, and client-side clipboard manipulation to swap onion mirror addresses for traffic steering/resilience.
Kraken is a ransomware-as-a-service (RaaS) operation known for targeting multiple platforms, including Windows, Linux, and VMware ESXi, using customized encryptors for each environment. It is linked to the remnants of the HelloKitty ransomware cartel.
Russian-speaking ransomware group conducting big-game hunting and double-extortion operations; described as emerging from remnants of the HelloKitty ransomware cartel.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.