HelloKitty, also known as Kitty, is a human-operated ransomware family first observed in late 2020. It encrypts victim data and presents customized ransom notes that direct victims to Tor-based negotiation and payment portals. Windows variants have used AES encryption with RSA-2048 or NTRU public-key protection, while Linux variants have used AES-256 with ECDH-based key protection. Variants have been implemented in C++ and Go.
HelloKitty disables processes and services that could impede encryption, including enterprise application, database, messaging, backup, and web-server components. It can enumerate running processes and network resources, terminate selected processes and services, and delete shadow copies. Windows samples use built-in utilities, WMI, and the Windows Restart Manager API to identify and stop processes. The family uses a mutex to prevent concurrent execution.
HelloKitty has Windows and Linux encryptors, including Linux ELF payloads designed for VMware ESXi hosts. Its ESXi-focused variant uses the ESXi management interface to enumerate running virtual machines and attempts graceful, hard, and forced VM shutdown before encrypting virtual-disk, metadata, and snapshot files. Targeting hypervisors enables a single ransomware deployment to disrupt multiple virtualized workloads.
HelloKitty was provisionally linked to the February 2021 ransomware attack against CD Projekt Red, where attackers encrypted systems and claimed theft of game source code and internal business data. HelloKitty-associated activity has also been linked to exploitation of vulnerable SonicWall remote-access appliances and Apache ActiveMQ systems. The family has been used in campaigns against organizations globally, including enterprises and virtualization infrastructure. Phishing and secondary deployment following other malware infections have also been reported as delivery methods.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Active exploitation of the Apache ActiveMQ vulnerability CVE-2023-46604 is being used to download and infect Linux systems with Kinsing malware. The flaw results from OpenWire commands failing to validate Throwable class types during unmarshalling, enabling remote code execution. | The content notes reports of active exploitation of CVE-2023-46604 by threat actors, including those behind the HelloKitty ransomware family.
CrowdStrike security researcher Heather Smith told BleepingComputer yesterday that the targeted vulnerability is tracked as CVE-2019-7481. "This exploitation targets a long-known vulnerability that was patched in newer versions of firmware released in early 2021," SonicWall said. | BleepingComputer was told by a source in the cybersecurity industry that HelloKitty has been exploiting the vulnerability for the past few weeks. CrowdStrike also confirmed ... that the ongoing attacks are attributed to multiple threat actors, including HelloKitty.
The TTPs are nothing new. They include initial network access through compromised credentials, exploitation of known vulnerabilities (e.g., PrintNightmare)
Mandiant said in April that the CVE-2021-20016 SMA 100 zero-day was exploited to deploy a new ransomware strain known as FiveHands... Before patches were released in late February 2021, the same bug was abused indiscriminately in the wild.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
HelloKitty samples were retrieved from their campaigns targeting Linux systems at the end of 2021... Oldest samples from 2021 are HelloKitty ransomware for Linux (ELF binaries), and most recent ones (June 2022) are Zeppelin ransomware.
In July 2021 an encryptor that targeted explicitly VMware ESXi systems was discovered.
This activity group also developed and deployed the FiveHands and HelloKitty ransomware payloads and often gained access to an organization via DEV-0193’s BazaLoader infrastructure.
A threat actor has leaked the complete source code for the first version of the HelloKitty ransomware on a Russian-speaking hacking forum, claiming to be developing a new, more powerful encryptor.
HELLOKITTY ransomware—used to target Polish video game developer CD Projekt Red—is reportedly built from DEATHRANSOM.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
When executed, HelloKitty terminates 1,706 processes, shuts down 57 services and deletes shadow copies via Windows Management Instrumentation.
In these cases, the threat actors were able to delete cloud-stored backups prior to ransomware deployment.
By targeting virtual machines, ransomware operators can also encrypt multiple servers at once with a single command. In June, researchers spotted a new REvil ransomware Linux encryptor designed to target VMware ESXi virtual machines, a popular enterprise virtual machine platform.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
APT1 listed connected network shares. APT32 used the net view command to show all shares available, including the administrative shares such as C$ and ADMIN$. APT41 used the net share command as part of network reconnaissance.
By targeting virtual machines, ransomware operators can also encrypt multiple servers at once with a single command. In June, researchers spotted a new REvil ransomware Linux encryptor designed to target VMware ESXi virtual machines, a popular enterprise virtual machine platform.
threat actors claimed to have stolen full copies of the source code for Cyberpunk 2077, The Witcher 3, Gwent and an unreleased version of The Witcher 3, along with documents relating to accounting, administration, legal, HR, investor relations and more.
CD Projekt confirmed via Twitter that an unidentified actor had gained access to their internal network, encrypted some devices on the network and stolen data.
When executed, HelloKitty terminates 1,706 processes, shuts down 57 services and deletes shadow copies via Windows Management Instrumentation.
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
48 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family whose operators are cited as actively exploiting CVE-2023-46604.
Named ransomware group referenced as a destination for former Conti members; no additional technical details provided.
Linux-targeting ransomware samples used in Vice Society campaigns at the end of 2021, carrying the Vice Society ransom note.
Ransomware family/cartel referenced as the predecessor/remnant source for the Kraken group.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.