HelloKitty ransomware emerged as a targeted extortion threat that gained broad attention after being linked to the attack on game studio CD Projekt Red. Researchers described the malware as less stealthy than major families such as Ryuk, REvil, and Conti, but still highly disruptive, with operators using Tor-based payment portals, customized ransom notes, and in some cases auctioning stolen data on underground forums. The family has also been referred to as Kitty, and reporting tied it to later variants and related offshoots including FiveHands, Kitty Go, Kitty Linux, Vice Society, and Boombye.

TTPs, infrastructure, and targeting history in one profile.
7 events from the most recent confirmed update back to the earliest known activity.
Vice Society emerged in June 2021 as a probable HelloKitty spin-off. The variant used Windows and Linux encryption based on OpenSSL, according to the profile.
On May 9, 2021, the Kitty Go variant targeted Western Pathology in the United States. Its ransom note claimed the attackers had stolen more than 1 TB of data from the victim.
Reporting cited by SentinelLabs said data stolen from CD Projekt Red was being auctioned on underground forums. The reported sale appeared legitimate at the time of writing.
CD Projekt Red disclosed that it had suffered a targeted and highly impactful ransomware attack. SentinelLabs reported the attack was widely attributed to the HelloKitty ransomware family.
A HelloKitty variant dated January 28, 2021 used the .crypted extension and dropped the ransom note read_me_lkd.txt. The variant reflects continued evolution of the ransomware family after its initial emergence.
A late-December 2020 HelloKitty variant targeted Brazilian companies and referenced CEMIG in its extortion message. This variant used the .kitty extension and the ransom note read_me_lkdtt.txt.
HelloKitty ransomware activity began around mid-November 2020 and was oriented primarily toward English-speaking victims while spreading globally. Multiple sources describe the family as first seen in late 2020.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
labs.sentinelone.com
Open sourceblog.emsisoft.com
Open sourceid-ransomware.blogspot.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.