Hellcat Ransomware is a ransomware threat referenced in Splunk analytic stories and detection content. The provided content associates it with ransomware-related detection coverage including ransomware notes, service termination, exploitation of vulnerabilities in CrushFTP, FortiNAC, and Jenkins, credential theft activity involving Mimikatz, VaultCLI, and SSH keys, use of post-exploitation tooling such as PowerShell Empire and SliverC2, data exfiltration, and phishing attempts. Additional detection context links Hellcat Ransomware to Windows-focused monitoring for suspicious FTP connections from non-standard process paths, a behavior noted as relevant to command-and-control and data exfiltration. The content does not provide specific technical details on the malware’s internal functionality, initial access mechanism, encryption behavior, targeted industries, associated threat actor, or concrete indicators of compromise beyond this detection context.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Related Detections ... Dump LSASS via procdump ... Creation of lsass Dump with Taskmgr ... Access LSASS Memory for Dump Creation ... Detect Credential Dumping through LSASS access ... Dump LSASS via comsvcs DLL ... Windows Credential Dumping LSASS Memory Createdump ... Windows Possible Credential Dumping
The following analytic detects the modification of firewall settings to allow file and printer sharing. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on command-line executions involving 'netsh' commands that enable file and printer sharing.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated Analytic Story Handala Wiper [[URL_245455be_27]] Hellcat Ransomware [[URL_245455be_28]] Living Off The Land
Ransomware that is associated with a wide range of attack techniques, including exploitation of vulnerabilities, credential theft, post-exploitation tools, and data exfiltration.
Associated Analytic Story AgentTesla ... Hellcat Ransomware ... Snake Keylogger
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.