HellCat is a cybercriminal ransomware and extortion ecosystem that emerged in mid-2024 and has been closely associated with members of the BreachForums underground community. The operation appears to be structured as a multi-actor ecosystem rather than a single cohesive team, with distinct personas linked to administration, coordination, and access brokering. Reported HellCat-linked personas include Rey, who has been described as an administrator or coordinating figure and has also used the alias Hikki-Chan, and Miyako, an initial access broker advertising footholds such as remote code execution, administrative access, firewall access, and VPN entry. The ecosystem has also been referred to as GOLD PUMPKIN in some reporting. HellCat has targeted enterprise environments and has been associated with intrusions affecting automotive, industrial, and technology-related organizations. Publicly reported victims and claimed victims include Jaguar Land Rover, Schneider Electric, and Ascom. In multiple cases, access was reportedly obtained through credentials harvested by infostealer malware and then used to compromise enterprise platforms such as Atlassian Jira. HellCat activity has been tied to theft and leakage of internal documents, source code, project data, employee information, and other sensitive corporate records, indicating a strong emphasis on data exfiltration and extortion pressure. Observed tradecraft includes credential theft through use of infostealer-derived logs and tools such as Mimikatz, theft of SSH keys and other secrets, phishing, exploitation of enterprise-facing vulnerabilities, use of post-exploitation frameworks such as PowerShell Empire and Sliver, abuse of SQL Server functionality, certificate export activity, service termination associated with ransomware deployment, and broad post-compromise operations. Reporting also links HellCat intrusions to exploitation of products such as CrushFTP, FortiNAC, and Jenkins in detection coverage. The group’s intrusion lifecycle commonly spans initial access, credential theft, lateral movement, post-exploitation, data exfiltration, persistence, and defense evasion. HellCat has been described as a ransomware group, but available reporting most consistently supports data theft and extortion activity, with leak-site publication used as a coercive mechanism. The ecosystem’s reliance on access brokers, underground forum administration, and infostealer-sourced credentials reflects a modern cybercrime division of labor in which access acquisition, intrusion operations, and monetization are distributed across linked actors.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a ransomware group that breached victims via Jira credentials obtained from infostealer logs.
Referenced as the ransomware ecosystem from which Sukob reportedly originated; no direct operational details for this campaign are provided beyond that association.
Structured ransomware ecosystem that relies on a supporting access layer to obtain and transfer compromised network access into victim environments.
A named cybercriminal ecosystem/group discussed in connection with data leaks, underground forum activity, and administrative coordination. The content centers on a persona, Rey, assessed as holding an administrative or coordinating role within HellCat-linked activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.