HelloKitty is a human-operated ransomware operation active since November 2020 that conducts enterprise-focused intrusions involving data theft and file encryption. The group is widely associated with double-extortion activity, pressuring victims by threatening to leak stolen data in addition to encrypting systems. It became especially well known for the February 2021 attack on CD Projekt Red, in which the operators claimed to have stolen game source code and internal corporate documents. Reported victims and targeting indicate activity against large companies across multiple regions, including organizations in Poland, Brazil, and the United States. HelloKitty has been linked to exploitation of edge-device vulnerabilities for initial access, including SonicWall SMA/SRA flaws, and has also been described as leveraging common intrusion vectors such as exposed remote access services, phishing, malicious downloads, botnets, and exploit-driven compromise. The operation is characterized as hands-on-keyboard and enterprise-oriented rather than opportunistic commodity ransomware. Technically, HelloKitty has used Windows and Linux encryptors, with Linux variants observed targeting VMware ESXi environments to maximize impact against virtualized infrastructure. Reported behavior includes terminating processes and services, deleting volume shadow copies, and encrypting files with strong hybrid cryptographic schemes. The family has been described as written in C++, with later variants and related tooling also appearing in Go. HelloKitty’s extortion workflow has used Tor-based negotiation infrastructure, and the operation has been associated with theft of corporate data prior to encryption. The malware family and operation have also been referenced under the names Kitty, Hello_Kitty, DeathRansom, and DeathKitty, and have genealogical or operational links reported with FiveHands. Later reporting has suggested possible continuity or code reuse involving Abyss Locker, while Kraken has been described as emerging from remnants of the HelloKitty cartel. Vice Society has also been described as a probable spin-off in some reporting. In 2024, the original HelloKitty source code was reportedly leaked by an actor claiming to be its creator, increasing the likelihood of copycat reuse and complicating attribution for later derivatives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as a strong ransomware brand admired for recognition and marketing value.
Referenced as a ransomware group that some former Conti members allegedly joined after Conti’s retirement; described here as no longer active.
HelloKitty is a defunct or diminished ransomware cartel, with remnants linked to the emergence of the Kraken ransomware operation.
Referenced as a ransomware cartel whose remnants are associated with the emergence of the Kraken group.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.