Hello Kitty, also referred to as Hello Kitty/FiveHands, is a ransomware family first observed by the FBI in January 2021. Its operators conduct double-extortion attacks, exfiltrating victim data before encrypting systems and threatening public release or sale of stolen material if demands are not met. They may also conduct distributed denial-of-service attacks against victims’ public-facing websites to increase pressure. Observed initial-access methods include compromised credentials and exploitation of SonicWall vulnerabilities CVE-2021-20016, CVE-2021-20021, CVE-2021-20022, and CVE-2021-20023. Intrusions have involved Cobalt Strike, Commando, PowerShell Empire, BloodHound, and Mimikatz for network discovery, privilege escalation, and data theft. Hello Kitty/FiveHands has been deployed by the financially motivated Vice Society, also tracked as Vanilla Tempest and VICE SPIDER, which has targeted education, healthcare, IT, and manufacturing organizations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Hello Kitty/FiveHands ransomware uses compromised credentials or known vulnerabilities in SonicWall products (CVE-2021-20016, CVE-2021-20021, CVE-202120022, CVE-2021-20023). | The FBI first observed Hello Kitty/FiveHands ransomware in January 2021. Hello Kitty/FiveHands actors aggressively apply pressure to victims typically using the double extortion technique.
Hello Kitty/FiveHands ransomware uses compromised credentials or known vulnerabilities in SonicWall products (CVE-2021-20016, CVE-2021-20021, CVE-202120022, CVE-2021-20023). | The FBI first observed Hello Kitty/FiveHands ransomware in January 2021. Hello Kitty/FiveHands actors aggressively apply pressure to victims typically using the double extortion technique.
Hello Kitty/FiveHands ransomware uses compromised credentials or known vulnerabilities in SonicWall products (CVE-2021-20016, CVE-2021-20021, CVE-202120022, CVE-2021-20023). | The FBI first observed Hello Kitty/FiveHands ransomware in January 2021. Hello Kitty/FiveHands actors aggressively apply pressure to victims typically using the double extortion technique.
Hello Kitty/FiveHands ransomware uses compromised credentials or known vulnerabilities in SonicWall products (CVE-2021-20016, CVE-2021-20021, CVE-202120022, CVE-2021-20023). | The FBI first observed Hello Kitty/FiveHands ransomware in January 2021. Hello Kitty/FiveHands actors aggressively apply pressure to victims typically using the double extortion technique.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“VICE SPIDER: known for Zeppelin and Hello Kitty ransomware, it frequently pairs SystemBC with Cobalt Strike and PowerShell Empire.”
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as ransomware historically associated with VICE SPIDER and SystemBC usage.
Named ransomware family referenced as one of the third-party payloads used by Vice Society.
A third-party ransomware locker delivered in Vice Society attacks.
Ransomware operation cited as associated with post-Conti member migration/infiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.