Kraken is a Russian-speaking ransomware group and ransomware-as-a-service (RaaS) operation assessed by Cisco Talos as having emerged from the remnants of the HelloKitty ransomware cartel; reporting also describes it as a descendant or continuation of HelloKitty. The group conducts big-game hunting and double-extortion attacks, stealing data before encryption and listing victims on its leak site across multiple countries including the United States, the United Kingdom, Canada, Panama, Kuwait, and Denmark. Kraken targets Windows, Linux, and VMware ESXi environments using platform-specific encryptors. Cisco Talos reported that the group benchmarks victim machines before encryption to decide between full and partial encryption. Observed tradecraft includes exploitation of SMB vulnerabilities on internet-facing assets for initial access, theft of administrative credentials, re-entry via RDP, deployment of Cloudflared reverse tunnels, and use of SSHFS for data exfiltration. Prior to encryption, Kraken deletes shadow volumes, clears the Recycle Bin, and stops backup services. The Windows variant includes modules for encrypting Microsoft SQL data files, local drives, network shares, and Hyper-V virtual disks. The Linux/ESXi variant enumerates and terminates virtual machines to unlock disk files for encryption. Encrypted files may receive the .zpsc extension, ransom notes named readme_you_ws_hacked.txt are dropped, and a cleanup script named bye_bye.sh removes logs, shell history, and the ransomware binary after execution. Cisco Talos observed Kraken activity in August 2025 and reported at least one case involving a $1 million Bitcoin ransom demand. The group has also been reported to have launched an underground forum called The Last Haven Board. Known alias from the provided content: kraken.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced by The Gentlemen members as another ransomware program or group in their orbit and as a possible alternative affiliation.
Darknet marketplace ecosystem using a hybrid clearnet/Tor architecture: clearnet CAPTCHA/login gateway domains broker sessions and route users to onion-hosted backend services. Observed behaviors include pre-authentication session binding via routing endpoints, Tor-aware routing cookies, distributed rotating gateway domains for redundancy, and client-side clipboard manipulation to swap onion mirror addresses for traffic steering/resilience.
Kraken is a ransomware-as-a-service (RaaS) operation known for targeting multiple platforms, including Windows, Linux, and VMware ESXi, using customized encryptors for each environment. It is linked to the remnants of the HelloKitty ransomware cartel.
Russian-speaking ransomware group conducting big-game hunting and double-extortion operations; described as emerging from remnants of the HelloKitty ransomware cartel.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.