Kraken
Kraken is a ransomware operation and ransomware-as-a-service (RaaS) threat that emerged in 2025 and is linked to remnants of the HelloKitty ransomware cartel; Cisco Talos described it as a Russian-speaking group and a descendant/continuation of HelloKitty. It conducts big-game hunting and double-extortion attacks, stealing data before encryption and using leak-site pressure. Kraken targets Windows, Linux, and VMware ESXi environments with distinct platform-specific encryptors. Talos reported that the malware benchmarks each victim machine before encryption to determine whether to use full or partial encryption without overloading the system. Observed intrusion activity includes exploitation of SMB vulnerabilities for initial access, theft of administrative credentials, re-entry via RDP, and use of Cloudflared reverse tunnels and SSHFS for lateral movement and data exfiltration. Before encryption, Kraken deletes shadow volumes, clears the Recycle Bin, and stops backup services. The Windows variant includes modules to encrypt Microsoft SQL Server data files, local drives, reachable network shares, and Hyper-V virtual disk files. The Linux/ESXi variant enumerates and forcibly terminates virtual machines to unlock disk files for encryption. After execution, a cleanup script named bye_bye.sh removes logs, shell history, the ransomware binary, and the script itself. Reported file artifacts include the .zpsc extension on encrypted files and a ransom note named readme_you_ws_hacked.txt. Cisco Talos observed at least one case with a $1 million ransom demand in Bitcoin. Kraken has also been associated with a cybercrime forum called “The Last Haven Board.” Victims listed on its leak sites were reported in the United States, United Kingdom, Canada, Panama, Kuwait, and Denmark.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Techniques & procedures
2 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
1 technique
Initial Access
Impact
1 technique
Impact
IOCs tracked for this family
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
Other indicator types observed in public reporting.
Recent activity
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Kraken ransomware is identified as a significant new player in the 2025 ransomware landscape, operating as a ransomware-as-a-service (RaaS) and contributing to the ongoing fragmentation and rapid evolution of ransomware families.
Low-volume ransomware brand referenced as part of the long-tail of operators.
Kraken is a ransomware-as-a-service (RaaS) operation that targets multiple platforms, including Windows, Linux, and VMware ESXi. It uses customized encryptors for each platform and is linked to the former HelloKitty ransomware group.
Ransomware associated with big-game hunting and double-extortion activity (noted by Talos in Aug 2025).
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.