HelloKitty is a human-operated ransomware family first observed in late 2020 and associated with high-impact enterprise intrusions, including the attack on CD Projekt Red. It is also referred to as Kitty and has been linked in some reporting to related or descendant strains such as FiveHands, Kitty Go, Kitty Linux, Boombye, and Vice Society-associated Linux deployments. The family has targeted organizations globally, with reporting indicating a focus on English-speaking victims and enterprise environments.
HelloKitty encrypts victim data and delivers ransom notes directing victims to Tor-based negotiation portals. Multiple variants have been documented across Windows and Linux, including ELF encryptors built to target VMware ESXi infrastructure. ESXi-focused variants enumerate running virtual machines and attempt to shut them down with native management commands before encrypting virtual machine-related files, allowing a single compromise to disrupt many hosted systems at once. Linux and ESXi samples have been observed in the wild since 2021, and some campaigns used HelloKitty against Linux systems in operations later associated with Vice Society.
On Windows, HelloKitty is known for aggressively terminating processes and services that could interfere with encryption, including enterprise application and database components. It can enumerate running processes, identify specific targets for termination, and enumerate network resources or shares. Reported behavior also includes deleting shadow copies and using mutex-based single-instance controls. Variants have been described as using strong hybrid cryptography, with reporting citing combinations such as AES with RSA, and some variants using NTRU or ECDH-based schemes. No reliable public weaknesses in its encryption are widely established.
Delivery and initial access reporting is mixed, but HelloKitty has been associated with targeted intrusions following exploitation of exposed enterprise systems and vulnerabilities, including SonicWall appliance exploitation and deployment via other post-compromise activity. Broader reporting has also mentioned phishing and secondary-payload delivery in some cases, but the strongest support is for hands-on, enterprise-focused ransomware deployment rather than commodity mass distribution.
HelloKitty has been used in double-extortion style incidents in which attackers both encrypt systems and steal data to pressure victims. The family is not consistently described as a ransomware-as-a-service platform; some reporting instead characterizes it as tooling used by specific operators, including later use by Vice Society for Linux encryption. Overall, HelloKitty is notable for its cross-platform evolution, ESXi targeting, aggressive process disruption, and role in prominent enterprise ransomware campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CrowdStrike security researcher Heather Smith told BleepingComputer yesterday that the targeted vulnerability is tracked as CVE-2019-7481. "This exploitation targets a long-known vulnerability that was patched in newer versions of firmware released in early 2021," SonicWall said. | BleepingComputer was told by a source in the cybersecurity industry that HelloKitty has been exploiting the vulnerability for the past few weeks. CrowdStrike also confirmed ... that the ongoing attacks are attributed to multiple threat actors, including HelloKitty.
Red Canary detected an adversary executing discovery commands on dozens of cloud-based Linux endpoints vulnerable to a critical remote code vulnerability (CVE-2023-46604) in Apache ActiveMQ... Security researchers have previously identified adversaries exploiting CVE-2023-46604 for malware deployment, to spread TellYouThePass, Ransomhub and HelloKitty ransomware, along with Kinsing... Finally, the adversary used curl to download two ActiveMQ JAR files... These two JAR files constitute a legitimate patch for CVE-2023-46604. | Security researchers have previously identified adversaries exploiting CVE-2023-46604 for malware deployment, to spread TellYouThePass, Ransomhub and HelloKitty ransomware...
The TTPs are nothing new. They include initial network access through compromised credentials, exploitation of known vulnerabilities (e.g., PrintNightmare)
Mandiant said in April that the CVE-2021-20016 SMA 100 zero-day was exploited to deploy a new ransomware strain known as FiveHands... Before patches were released in late February 2021, the same bug was abused indiscriminately in the wild.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
HelloKitty samples were retrieved from their campaigns targeting Linux systems at the end of 2021... Oldest samples from 2021 are HelloKitty ransomware for Linux (ELF binaries), and most recent ones (June 2022) are Zeppelin ransomware.
In July 2021 an encryptor that targeted explicitly VMware ESXi systems was discovered.
This activity group also developed and deployed the FiveHands and HelloKitty ransomware payloads and often gained access to an organization via DEV-0193’s BazaLoader infrastructure.
A threat actor has leaked the complete source code for the first version of the HelloKitty ransomware on a Russian-speaking hacking forum, claiming to be developing a new, more powerful encryptor.
HELLOKITTY ransomware—used to target Polish video game developer CD Projekt Red—is reportedly built from DEATHRANSOM.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
When executed, HelloKitty terminates 1,706 processes, shuts down 57 services and deletes shadow copies via Windows Management Instrumentation.
In these cases, the threat actors were able to delete cloud-stored backups prior to ransomware deployment.
By targeting virtual machines, ransomware operators can also encrypt multiple servers at once with a single command. In June, researchers spotted a new REvil ransomware Linux encryptor designed to target VMware ESXi virtual machines, a popular enterprise virtual machine platform.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
APT1 listed connected network shares. APT32 used the net view command to show all shares available, including the administrative shares such as C$ and ADMIN$. APT41 used the net share command as part of network reconnaissance.
By targeting virtual machines, ransomware operators can also encrypt multiple servers at once with a single command. In June, researchers spotted a new REvil ransomware Linux encryptor designed to target VMware ESXi virtual machines, a popular enterprise virtual machine platform.
threat actors claimed to have stolen full copies of the source code for Cyberpunk 2077, The Witcher 3, Gwent and an unreleased version of The Witcher 3, along with documents relating to accounting, administration, legal, HR, investor relations and more.
CD Projekt confirmed via Twitter that an unidentified actor had gained access to their internal network, encrypted some devices on the network and stolen data.
When executed, HelloKitty terminates 1,706 processes, shuts down 57 services and deletes shadow copies via Windows Management Instrumentation.
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
47 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named ransomware group referenced as a destination for former Conti members; no additional technical details provided.
Linux-targeting ransomware samples used in Vice Society campaigns at the end of 2021, carrying the Vice Society ransom note.
Ransomware family/cartel referenced as the predecessor/remnant source for the Kraken group.
Referenced as a prior/notorious ransomware operation/cartel whose remnants are linked to Kraken.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.