HelloKitty is a ransomware family observed since late 2020 that encrypts victim data and demands payment for decryption. It targets Windows and Linux systems, with dedicated encryptors for VMware ESXi virtualization infrastructure. Implementations include C++ and Go variants. Windows variants use hybrid encryption combining per-file AES keys with an embedded RSA-2048 public key. The malware discovers network resources and searches for processes to terminate before encryption. Variants also stop services and delete volume shadow copies to interfere with recovery. ESXi encryptors attempt to shut down virtual machines using the esxcli management utility before encrypting their files. Encrypted-file extensions and ransom-note formats vary across variants and campaigns.
Vice Society used HelloKitty as a primary ransomware payload during its early operations in 2021, including campaigns against Linux systems. The group conducts human-operated double-extortion attacks and has disproportionately targeted education and healthcare organizations. Data theft, credential compromise, and lateral movement in those operations are associated with the attackers' broader intrusion workflows rather than established native HelloKitty capabilities. HelloKitty deployment has also been observed following exploitation of CVE-2023-46604, a remote code execution vulnerability in Apache ActiveMQ, including attacks against systems in South Korea. Operators use ransom notes and private communication channels to negotiate payment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2023-46604 is a remote code execution vulnerability in the Apache ActiveMQ server. The vulnerability began to be exploited shortly after its disclosure, with attack cases involving the Andariel group, HelloKitty ransomware, and Cobalt Strike observed in systems within Korea.
CrowdStrike security researcher Heather Smith told BleepingComputer yesterday that the targeted vulnerability is tracked as CVE-2019-7481. "This exploitation targets a long-known vulnerability that was patched in newer versions of firmware released in early 2021," SonicWall said. | BleepingComputer was told by a source in the cybersecurity industry that HelloKitty has been exploiting the vulnerability for the past few weeks. CrowdStrike also confirmed ... that the ongoing attacks are attributed to multiple threat actors, including HelloKitty.
The TTPs are nothing new. They include initial network access through compromised credentials, exploitation of known vulnerabilities (e.g., PrintNightmare)
Mandiant said in April that the CVE-2021-20016 SMA 100 zero-day was exploited to deploy a new ransomware strain known as FiveHands... Before patches were released in late February 2021, the same bug was abused indiscriminately in the wild.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
At the start of the group’s observed operations in 2021, Vice Society affiliates used the HelloKitty Ransomware variant as a primary payload in their infection chain.
In July 2021 an encryptor that targeted explicitly VMware ESXi systems was discovered.
This activity group also developed and deployed the FiveHands and HelloKitty ransomware payloads and often gained access to an organization via DEV-0193’s BazaLoader infrastructure.
A threat actor has leaked the complete source code for the first version of the HelloKitty ransomware on a Russian-speaking hacking forum, claiming to be developing a new, more powerful encryptor.
HELLOKITTY ransomware—used to target Polish video game developer CD Projekt Red—is reportedly built from DEATHRANSOM.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
In these cases, the threat actors were able to delete cloud-stored backups prior to ransomware deployment.
By targeting virtual machines, ransomware operators can also encrypt multiple servers at once with a single command. In June, researchers spotted a new REvil ransomware Linux encryptor designed to target VMware ESXi virtual machines, a popular enterprise virtual machine platform.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
APT1 listed connected network shares. APT32 used the net view command to show all shares available, including the administrative shares such as C$ and ADMIN$. APT41 used the net share command as part of network reconnaissance.
By targeting virtual machines, ransomware operators can also encrypt multiple servers at once with a single command. In June, researchers spotted a new REvil ransomware Linux encryptor designed to target VMware ESXi virtual machines, a popular enterprise virtual machine platform.
threat actors claimed to have stolen full copies of the source code for Cyberpunk 2077, The Witcher 3, Gwent and an unreleased version of The Witcher 3, along with documents relating to accounting, administration, legal, HR, investor relations and more.
Vice Society is known for its extortion tactics, encrypting devices and demanding a ransom.
When executed, HelloKitty terminates 1,706 processes, shuts down 57 services and deletes shadow copies via Windows Management Instrumentation.
26 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
59 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware used to evaluate how backup timing affects clean-file preservation and the number of backups created. The abstract provides no family-specific behavior or results.
Ransomware family whose operators are cited as actively exploiting CVE-2023-46604.
Named ransomware group referenced as a destination for former Conti members; no additional technical details provided.
Linux-targeting ransomware samples used in Vice Society campaigns at the end of 2021, carrying the Vice Society ransom note.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.