HELLOKITTY

MITRE ATT&CK: S0617 View on attack.mitre.org

Aliases: FiveHands, HELLOKITTY

First seen
2020-01-01 00:00:00
Malware type
ransomware
Family
Malware family
Operating systems
windows
Related IoCs
9 (9 malicious)
Last IoC activity
2026-08-02 10:25:33
Profile updated
2026-07-07 13:03:03

Targeted industries: media-and-entertainment energy-and-utilities

Targeted regions: country_code:pl country_code:br

Context

HELLOKITTY is a ransomware written in C++ that shares similar code structure and functionality with DEATHRANSOM and FIVEHANDS. HELLOKITTY has been used since at least 2020, targets have included a Polish video game developer and a Brazilian electric power company.

Recent IoC activity

9 malicious indicators in Maltiverse are attributed to HELLOKITTY (S0617). The 9 most recently updated:

TypeIndicatorUpdatedSources
file sample file 2026-08-02 2
file sample 0004 2026-06-27 2
file sample 7bdb0be5e4c376bbb3533b8872f3ba72b7876ef261b94f6799010f55160d8adb 2026-06-26 2
file sample 50305e831923c6aabf53b18dddd656e7337fe4b56433291d5841b068a66a5af9.zip 2026-06-23 1
file sample Hi_Kitty_2.exe 2026-06-19 3
file sample 947e357bfdfe411be6c97af6559fd1cdc5c9d6f5cea122bf174d124ee03d2de8.bin 2026-02-14 1
hostname decrypts3nln3tic.onion 2025-04-12 1
hostname x6gjpqs4jjvgpfvhghdz2dk7be34emyzluimticj5s5fexf4wa65ngad.onion 2025-04-12 1
hostname 6x7dp6h3w6q3ugjv4yv5gycj3femb24kysgry5b44hhgfwc5ml5qrdad.onion 2025-04-12 1

Detection coverage

  • 7 YARA rules
  • 90 Sigma rules

Malware & tools used

  • Data Encrypted for Impact (attack-pattern)
  • Inhibit System Recovery (attack-pattern)
  • Network Share Discovery (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Local Storage Discovery (attack-pattern)
  • Process Discovery (attack-pattern)

Detection rules

  • TRELLIX_ARC_Ransom_Linux_Hellokitty_0721 (yara-rule)
  • ARKBIRD_SOLG_RAN_ELF_Hellokitty_Aug_2021_1 (yara-rule)
  • DITEKSHEN_MALWARE_Win_Kitty (yara-rule)
  • DITEKSHEN_MALWARE_Linux_Hellokitty (yara-rule)
  • SIGNATURE_BASE_APT_UNC2447_MAL_RANSOM_Hellokitty_May21_1 (yara-rule)
  • SIGNATURE_BASE_APT_UNC2447_MAL_RANSOM_Hellokitty_May21_2 (yara-rule)
  • MALPEDIA_Win_Hellokitty_Auto (yara-rule)

Reports & references

  • Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
  • advintel.io — Enter Karakurt Data Extortion Arm Of Prolific Ransomware Group (report)
  • blogs.vmware.com — Esxi Targeting Ransomware The Threats That Are After Your Virtual Machines Part 1 (report)
  • CrowdStrike — Hypervisor Jackpotting Ecrime Actors Increase Targeting Of Esxi Servers (report)
  • vmware.com — Vmw Exposing Malware In Linux Based Multi Cloud Environments (report)
  • Palo Alto Unit 42 — Emerging Ransomware Groups (report)
  • blog.bushidotoken.net — Gamer Cheater Hacker Spy (report)
  • blogs.vmware.com — Threat Report Illuminating Volume Shadow Deletion (report)
  • advintel.io — Discontinued The End Of Conti S Brand Marks New Chapter For Cybercrime Landscape (report)
  • esentire.com — Conti Affiliate Exposed New Domain Names Ip Addresses And Email Addresses Uncovered By Esentire (report)
  • blog.sekoia.io — Vice Society A Discreet But Steady Double Extortion Ransomware Group (report)
  • soolidsnake.github.io — Hellokitty Linux (report)
  • bleepingcomputer.com — Linux Version Of Hellokitty Ransomware Targets Vmware Esxi Servers (report)
  • govinfosecurity.com — Vice Society Ransomware Gang Disrupted Spar Stores A 18225 (report)
  • blog.malwarebytes.com — Hellokitty When Cyberpunk Met Cy Purr Crime (report)
  • id-ransomware.blogspot.com — Hellokitty Ransomware (report)
  • labs.sentinelone.com — Hellokitty Ransomware Lacks Stealth But Still Strikes Home (report)
  • medium.com — Static Unpacker And Decoder For Hello Kitty Packer 91A3E8844Cb7 (report)
  • twitter.com — 1359167108727332868 (report)
  • bleepingcomputer.com — Hellokitty Ransomware Is Targeting Vulnerable Sonicwall Devices (report)
  • cadosecurity.com — Punk Kitty Ransom Analysing Hellokitty Ransomware Attacks (report)
  • CISA — Aa22 249A (report)
  • CrowdStrike — New Ransomware Variant Uses Golang Packer (report)
  • databreaches.net — Babuk Re Organizes As Payload Bin Offers Its First Leak (report)
  • Mandiant — Unc2447 Sombrat And Fivehands Ransomware Sophisticated Financial Threat (report)

External references