hellcat
- First seen
- 2021-09-15 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Last IoC activity
- 2026-06-04 21:31:13
- Profile updated
- 2026-07-07 13:54:12
Targeted industries: government-and-public-sector financial-services
Targeted regions: country_code:us country_code:ru
Context
Hellcat is a ransomware family that primarily targets government and financial sectors in the US and Russia. It encrypts victim files and demands a ransom for decryption keys, utilizing sophisticated evasion techniques.
Reports & references
- ransomlook.io — Hellcat (report)
- bleepingcomputer.com — Schneider Electric Confirms Dev Platform Breach After Hacker Steals Data (report)
- securityboulevard.com — Schneider Electric Hellcat Richixbw (report)
- infostealers.com — Schneider Electric Hacked And Blackmailed Due To Lumma Infostealer Infection (report)