Hellcat is a ransomware group that emerged in mid-2024. The provided content states that its main operators are known to be senior members of the BreachForums community, and reporting by Cyfirma and Hudson Rock linked a hacker using the moniker "Rey" to the group. In March 2025, Hellcat was attributed with a significant compromise of Jaguar Land Rover (JLR): the group reportedly used Jira credentials to access JLR’s internal network and leaked 700 internal documents, including development logs, source code, and a large employee dataset containing usernames, email addresses, display names, and time zones. The content consistently associates Hellcat with ransomware activity and with post-compromise behaviors reflected in detection content, including abuse of Windows utilities and living-off-the-land techniques such as netsh, regsvcs, rundll32, PowerShell, BITSAdmin, SQL Server stored procedures, suspicious named pipes, service stopping, process termination bursts, ransomware note creation, network share file-copy activity, and ESXi SSH brute-force activity. High-confidence targeting information in the content is limited, but Hellcat is explicitly tied to enterprise victimization and the JLR intrusion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In March, the HELLCAT ransomware group leaked 700 internal documents, purportedly part of a compromise of JLR's internal network using Jira credentials and also included development logs, source code, and a large employee dataset with usernames, email addresses, display names, and time zones, according to an analysis by threat intelligence firm Cyfirma.
31 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
32 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family referenced in the associated analytic stories.
Ransomware family referenced in an associated analytic story.
Associated Analytic Story ... Hellcat Ransomware
Ransomware family mentioned as relevant to a detection for unusually frequent process termination, a behavior linked to ransomware execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.