FiveHands is a Windows ransomware family that emerged in early 2021 as a rewrite or variant in the DeathRansom-to-HelloKitty lineage. It has been associated with intrusions tracked as UNC2447 and later with a prolific Conti-linked affiliate tracked as DEV-0230. FiveHands has been deployed in hands-on-keyboard ransomware operations that also used SOMBRAT, Cobalt Strike, and common post-exploitation tooling, and it has been linked to exploitation of SonicWall SMA vulnerabilities, including CVE-2021-20016, to gain initial access to enterprise environments.
The malware encrypts victim files and drops ransom notes while taking steps to inhibit recovery. Reported behavior includes use of an embedded NTRU public key for file encryption, deletion of Volume Shadow Copies, and selective encryption through command-line arguments that restrict processing to specified directories. FiveHands can also enumerate network shares and mounted drives, indicating awareness of broader enterprise storage and opportunities to impact network-accessible data. Some observed loader components decode an embedded payload in memory before execution, reflecting an effort to stage the ransomware while reducing straightforward static exposure.
Operationally, FiveHands has appeared in extortion-focused intrusions against organizations in North America and Europe and has been discussed in connection with broader ransomware affiliate ecosystems overlapping with HelloKitty, Thieflock, and Conti-associated activity. Campaign reporting ties it to exploitation of perimeter appliances, especially SonicWall remote access infrastructure, followed by reconnaissance, lateral movement, and ransomware deployment. The family is notable both for its place in an evolving ransomware genealogy and for its use in targeted enterprise compromises rather than indiscriminate commodity distribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Hello Kitty/FiveHands ransomware uses compromised credentials or known vulnerabilities in SonicWall products (CVE-2021-20016, CVE-2021-20021, CVE-202120022, CVE-2021-20023).
Hello Kitty/FiveHands ransomware uses compromised credentials or known vulnerabilities in SonicWall products (CVE-2021-20016, CVE-2021-20021, CVE-202120022, CVE-2021-20023).
Hello Kitty/FiveHands ransomware uses compromised credentials or known vulnerabilities in SonicWall products (CVE-2021-20016, CVE-2021-20021, CVE-202120022, CVE-2021-20023).
Hello Kitty/FiveHands ransomware uses compromised credentials or known vulnerabilities in SonicWall products (CVE-2021-20016, CVE-2021-20021, CVE-202120022, CVE-2021-20023).
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
both operations are leveraging SonicWall exploits to deploy a Go variant of the FiveHands/HelloKitty/DeathKitty ransomware family
One of the most prolific and successful Conti affiliates—and the one responsible for developing the “Conti Manual” leaked in August 2021—is tracked as DEV-0230. This activity group also developed and deployed the FiveHands and HelloKitty ransomware payloads...
15 distinct techniques documented for this family, organized by ATT&CK tactic.
it uses Windows Management Instrumentation (WMI) to enumerate Volume Shadow copies using the command “ select * from Win32_ShadowCopy” and then deletes copies by ID (Win32_ShadowCopy.ID).
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
In these cases, the threat actors were able to delete cloud-stored backups prior to ransomware deployment.
Этот крипто-вымогатель шифрует данные пользователей с помощью комбинации алгоритмов AES-256 и RSA... К зашифрованным файлам добавляется расширение: .crypted
Akira will delete system volume shadow copies via PowerShell commands. Avaddon deletes backups and shadow copies using native system tools. Babuk has the ability to delete shadow volumes using vssadmin.exe delete shadows /all /quiet. BlackCat can delete shadow copies using vssadmin.exe delete shadows /all /quiet and wmic.exe Shadowcopy Delete; it can also modify the boot loader using bcdedit /set {default} recoveryenabled No.
42 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
28 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group/family referenced in connection with access to logistics-sector victims, likely leveraging SonicWall-related access for ransomware attacks.
Ransomware capable of deleting volume shadow copies on compromised hosts.
Ransomware that can enumerate network shares and mounted drives on a network.
Ransomware operation mentioned as another family known to use the NTRUEncrypt public-key encryption algorithm.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.