Hello Kitty, also referred to as FiveHands, is a ransomware family first publicly observed in 2021 and used in double-extortion intrusions. Operators associated with Hello Kitty/FiveHands typically steal data before encrypting systems and threaten public release or sale of the stolen information if victims do not pay. In some cases, the extortion pressure has reportedly been escalated with disruptive attacks against victims’ public-facing websites. The malware has been linked to high-profile enterprise compromises, including the attack on CD Projekt, where source code and internal documents were stolen.
Intrusions involving Hello Kitty/FiveHands have used compromised credentials and exploitation of internet-facing systems, including SonicWall vulnerabilities, for initial access. Post-compromise activity has included use of common offensive tooling for network mapping, privilege escalation, credential access, and lateral movement, such as Cobalt Strike, PowerShell Empire, BloodHound, Mimikatz, and remote administration utilities. Exfiltration commonly precedes encryption, consistent with modern ransomware tradecraft.
Hello Kitty has also appeared as a third-party payload used by other threat actors rather than exclusively by a single dedicated group. Vice Society in particular has been repeatedly reported deploying Hello Kitty/FiveHands alongside other ransomware families such as Zeppelin, reflecting an affiliate-style or multi-payload operational model. Reporting has also noted overlap between Hello Kitty and broader criminal ecosystems that include actors formerly associated with Conti. The malware primarily targets Windows enterprise environments and has been observed in attacks affecting sectors including education, healthcare, manufacturing, and technology, as well as other organizations selected for financially motivated extortion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Hello Kitty/FiveHands ransomware uses compromised credentials or known vulnerabilities in SonicWall products (CVE-2021-20016, CVE-2021-20021, CVE-202120022, CVE-2021-20023). | The FBI first observed Hello Kitty/FiveHands ransomware in January 2021. Hello Kitty/FiveHands actors aggressively apply pressure to victims typically using the double extortion technique.
Hello Kitty/FiveHands ransomware uses compromised credentials or known vulnerabilities in SonicWall products (CVE-2021-20016, CVE-2021-20021, CVE-202120022, CVE-2021-20023). | The FBI first observed Hello Kitty/FiveHands ransomware in January 2021. Hello Kitty/FiveHands actors aggressively apply pressure to victims typically using the double extortion technique.
Hello Kitty/FiveHands ransomware uses compromised credentials or known vulnerabilities in SonicWall products (CVE-2021-20016, CVE-2021-20021, CVE-202120022, CVE-2021-20023). | The FBI first observed Hello Kitty/FiveHands ransomware in January 2021. Hello Kitty/FiveHands actors aggressively apply pressure to victims typically using the double extortion technique.
Hello Kitty/FiveHands ransomware uses compromised credentials or known vulnerabilities in SonicWall products (CVE-2021-20016, CVE-2021-20021, CVE-202120022, CVE-2021-20023). | The FBI first observed Hello Kitty/FiveHands ransomware in January 2021. Hello Kitty/FiveHands actors aggressively apply pressure to victims typically using the double extortion technique.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Vice Society was observed deploying INC ransomware against the health care industry; this group has a long-standing habit of cycling through third-party payloads such as BlackCat, Rhysida, Hello Kitty, Zeppelin, and Quantum Locker.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named ransomware family referenced as one of the third-party payloads used by Vice Society.
A third-party ransomware locker delivered in Vice Society attacks.
Ransomware operation cited as associated with post-Conti member migration/infiltration.
Ransomware strain historically associated with Vice Society activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.