The Kraken ransomware group, a successor to the HelloKitty cartel, has emerged as a significant threat in 2025, conducting big-game hunting and double extortion attacks across multiple countries, including the United States, United Kingdom, Canada, Denmark, Panama, and Kuwait. Kraken targets enterprise environments running Windows, Linux, and VMware ESXi, leveraging Server Message Block (SMB) vulnerabilities for initial access, and employing tools such as Cloudflared for persistence and SSHFS for data exfiltration. Notably, Kraken benchmarks victim machines before encryption, a rare feature that allows the ransomware to optimize its encryption process and avoid overloading systems, choosing between full and partial encryption based on system performance.
Kraken's operations are characterized by the use of a data leak site for extortion, where stolen data is published if ransom demands are not met, and the deployment of ransom notes titled "readme_you_ws_hacked.txt". The group has also established a new underground forum, "The Last Haven Board," to facilitate secure communications within the cybercrime community. The ransomware's connection to the defunct HelloKitty operation is evident through similarities in tactics and ransom notes, as well as the timing of its emergence following HelloKitty's source code leak. Kraken's opportunistic targeting and advanced techniques underscore its growing impact on the global ransomware landscape.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
On November 13, 2025, Cisco Talos publicly disclosed its analysis of Kraken's tactics, cross-platform encryptors, benchmarking-based encryption logic, and links to HelloKitty. The reporting also noted that indicators of compromise were published in a GitHub repository.
In September 2025, Kraken promoted a new underground forum called 'The Last Haven Board,' claiming support or collaboration from the HelloKitty team and WeaCorp. The forum launch marked a public expansion of the group's underground presence beyond ransomware operations.
In August 2025, Cisco Talos observed a Kraken intrusion in which the attackers exploited SMB vulnerabilities on internet-exposed servers for initial access, stole privileged credentials, re-entered via RDP, and used Cloudflared reverse tunnels and SSHFS for exfiltration before encryption. In at least one observed case, the operators demanded about $1 million in Bitcoin.
Cisco Talos assessed that the Russian-speaking Kraken ransomware operation emerged from remnants of the HelloKitty cartel, based on similarities in tooling, ransom note naming, and leak-site references. The group developed cross-platform encryptors for Windows, Linux, and VMware ESXi and adopted double-extortion tactics.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourceblog.talosintelligence.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.