HelloKitty (ELF)

First seen
2021-08-01 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 13:02:56

Targeted industries: technology-and-telecommunications healthcare-and-pharmaceutical

Context

HelloKitty (ELF) is a Linux variant of the HelloKitty ransomware, known for targeting Linux systems, particularly in sectors like technology and healthcare. It encrypts files and demands ransom for decryption.

Reports & references

  • Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
  • blogs.vmware.com — Esxi Targeting Ransomware The Threats That Are After Your Virtual Machines Part 1 (report)
  • CrowdStrike — Hypervisor Jackpotting Ecrime Actors Increase Targeting Of Esxi Servers (report)
  • vmware.com — Vmw Exposing Malware In Linux Based Multi Cloud Environments (report)
  • Palo Alto Unit 42 — Emerging Ransomware Groups (report)
  • esentire.com — Conti Affiliate Exposed New Domain Names Ip Addresses And Email Addresses Uncovered By Esentire (report)
  • blog.sekoia.io — Vice Society A Discreet But Steady Double Extortion Ransomware Group (report)
  • soolidsnake.github.io — Hellokitty Linux (report)
  • bleepingcomputer.com — Linux Version Of Hellokitty Ransomware Targets Vmware Esxi Servers (report)
  • govinfosecurity.com — Vice Society Ransomware Gang Disrupted Spar Stores A 18225 (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Hellokitty (report)

External references