Hello Kitty is a ransomware family used to encrypt victim data and disrupt access to systems and network resources. It is frequently grouped with FiveHands in advisories under the designation Hello Kitty/FiveHands. The FBI first observed activity under this designation in January 2021. Its operators use double extortion, stealing sensitive information before encryption and threatening publication or sale if victims refuse to pay. Operators have also used distributed denial-of-service attacks against victims’ public-facing websites to increase pressure. Ransom demands are made in Bitcoin and tailored to victims’ assessed ability to pay.
Hello Kitty/FiveHands intrusions have involved compromised credentials and exploitation of SonicWall vulnerabilities, including CVE-2021-20016, CVE-2021-20021, CVE-2021-20022, and CVE-2021-20023. Operators use separate tools, including Cobalt Strike, PowerShell Empire, BloodHound, and Mimikatz, for post-compromise access, network discovery, and privilege escalation. Data theft and other intrusion activities are components of the wider attack operation rather than established native capabilities of the ransomware itself.
Vice Society, also tracked as Vanilla Tempest and VICE SPIDER, has deployed Hello Kitty/FiveHands alongside other ransomware families. Its campaigns have disproportionately targeted education, particularly K–12 institutions. Windows ransomware samples have been identified in Hello Kitty/FiveHands investigations. Hello Kitty is distinct from HelloKittyCat, a ransomware variant associated with TellYouThePass.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Hello Kitty/FiveHands ransomware uses compromised credentials or known vulnerabilities in SonicWall products (CVE-2021-20016, CVE-2021-20021, CVE-202120022, CVE-2021-20023). | The FBI first observed Hello Kitty/FiveHands ransomware in January 2021. Hello Kitty/FiveHands actors aggressively apply pressure to victims typically using the double extortion technique.
Hello Kitty/FiveHands ransomware uses compromised credentials or known vulnerabilities in SonicWall products (CVE-2021-20016, CVE-2021-20021, CVE-202120022, CVE-2021-20023). | The FBI first observed Hello Kitty/FiveHands ransomware in January 2021. Hello Kitty/FiveHands actors aggressively apply pressure to victims typically using the double extortion technique.
Hello Kitty/FiveHands ransomware uses compromised credentials or known vulnerabilities in SonicWall products (CVE-2021-20016, CVE-2021-20021, CVE-202120022, CVE-2021-20023). | The FBI first observed Hello Kitty/FiveHands ransomware in January 2021. Hello Kitty/FiveHands actors aggressively apply pressure to victims typically using the double extortion technique.
Hello Kitty/FiveHands ransomware uses compromised credentials or known vulnerabilities in SonicWall products (CVE-2021-20016, CVE-2021-20021, CVE-202120022, CVE-2021-20023). | The FBI first observed Hello Kitty/FiveHands ransomware in January 2021. Hello Kitty/FiveHands actors aggressively apply pressure to victims typically using the double extortion technique.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Instead, the actors have deployed versions of Hello Kitty/Five Hands and Zeppelin ransomware, but may deploy other variants in the future.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as ransomware historically associated with VICE SPIDER and SystemBC usage.
Named ransomware family referenced as one of the third-party payloads used by Vice Society.
A third-party ransomware locker delivered in Vice Society attacks.
Ransomware operation cited as associated with post-Conti member migration/infiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.