HELLOKITTY
MITRE ATT&CK: S0617 View on attack.mitre.org
Aliases: FiveHands, HELLOKITTY
- First seen
- 2020-01-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 9 (9 malicious)
- Last IoC activity
- 2026-08-02 10:25:33
- Profile updated
- 2026-07-07 13:03:03
Targeted industries: media-and-entertainment energy-and-utilities
Targeted regions: country_code:pl country_code:br
Context
HELLOKITTY is a ransomware written in C++ that shares similar code structure and functionality with DEATHRANSOM and FIVEHANDS. HELLOKITTY has been used since at least 2020, targets have included a Polish video game developer and a Brazilian electric power company.
Recent IoC activity
9 malicious indicators in Maltiverse are attributed to HELLOKITTY (S0617). The 9 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | file | 2026-08-02 | 2 |
| file sample | 0004 | 2026-06-27 | 2 |
| file sample | 7bdb0be5e4c376bbb3533b8872f3ba72b7876ef261b94f6799010f55160d8adb | 2026-06-26 | 2 |
| file sample | 50305e831923c6aabf53b18dddd656e7337fe4b56433291d5841b068a66a5af9.zip | 2026-06-23 | 1 |
| file sample | Hi_Kitty_2.exe | 2026-06-19 | 3 |
| file sample | 947e357bfdfe411be6c97af6559fd1cdc5c9d6f5cea122bf174d124ee03d2de8.bin | 2026-02-14 | 1 |
| hostname | decrypts3nln3tic.onion | 2025-04-12 | 1 |
| hostname | x6gjpqs4jjvgpfvhghdz2dk7be34emyzluimticj5s5fexf4wa65ngad.onion | 2025-04-12 | 1 |
| hostname | 6x7dp6h3w6q3ugjv4yv5gycj3femb24kysgry5b44hhgfwc5ml5qrdad.onion | 2025-04-12 | 1 |
Detection coverage
- 7 YARA rules
- 90 Sigma rules
Malware & tools used
- Data Encrypted for Impact (attack-pattern)
- Inhibit System Recovery (attack-pattern)
- Network Share Discovery (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Local Storage Discovery (attack-pattern)
- Process Discovery (attack-pattern)
Detection rules
- TRELLIX_ARC_Ransom_Linux_Hellokitty_0721 (yara-rule)
- ARKBIRD_SOLG_RAN_ELF_Hellokitty_Aug_2021_1 (yara-rule)
- DITEKSHEN_MALWARE_Win_Kitty (yara-rule)
- DITEKSHEN_MALWARE_Linux_Hellokitty (yara-rule)
- SIGNATURE_BASE_APT_UNC2447_MAL_RANSOM_Hellokitty_May21_1 (yara-rule)
- SIGNATURE_BASE_APT_UNC2447_MAL_RANSOM_Hellokitty_May21_2 (yara-rule)
- MALPEDIA_Win_Hellokitty_Auto (yara-rule)
Reports & references
- Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
- advintel.io — Enter Karakurt Data Extortion Arm Of Prolific Ransomware Group (report)
- blogs.vmware.com — Esxi Targeting Ransomware The Threats That Are After Your Virtual Machines Part 1 (report)
- CrowdStrike — Hypervisor Jackpotting Ecrime Actors Increase Targeting Of Esxi Servers (report)
- vmware.com — Vmw Exposing Malware In Linux Based Multi Cloud Environments (report)
- Palo Alto Unit 42 — Emerging Ransomware Groups (report)
- blog.bushidotoken.net — Gamer Cheater Hacker Spy (report)
- blogs.vmware.com — Threat Report Illuminating Volume Shadow Deletion (report)
- advintel.io — Discontinued The End Of Conti S Brand Marks New Chapter For Cybercrime Landscape (report)
- esentire.com — Conti Affiliate Exposed New Domain Names Ip Addresses And Email Addresses Uncovered By Esentire (report)
- blog.sekoia.io — Vice Society A Discreet But Steady Double Extortion Ransomware Group (report)
- soolidsnake.github.io — Hellokitty Linux (report)
- bleepingcomputer.com — Linux Version Of Hellokitty Ransomware Targets Vmware Esxi Servers (report)
- govinfosecurity.com — Vice Society Ransomware Gang Disrupted Spar Stores A 18225 (report)
- blog.malwarebytes.com — Hellokitty When Cyberpunk Met Cy Purr Crime (report)
- id-ransomware.blogspot.com — Hellokitty Ransomware (report)
- labs.sentinelone.com — Hellokitty Ransomware Lacks Stealth But Still Strikes Home (report)
- medium.com — Static Unpacker And Decoder For Hello Kitty Packer 91A3E8844Cb7 (report)
- twitter.com — 1359167108727332868 (report)
- bleepingcomputer.com — Hellokitty Ransomware Is Targeting Vulnerable Sonicwall Devices (report)
- cadosecurity.com — Punk Kitty Ransom Analysing Hellokitty Ransomware Attacks (report)
- CISA — Aa22 249A (report)
- CrowdStrike — New Ransomware Variant Uses Golang Packer (report)
- databreaches.net — Babuk Re Organizes As Payload Bin Offers Its First Leak (report)
- Mandiant — Unc2447 Sombrat And Fivehands Ransomware Sophisticated Financial Threat (report)