HelloKitty (Windows)

Aliases: KittyCrypt

First seen
2020-12-01 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 13:03:06

Targeted industries: technology-and-telecommunications financial-services healthcare-and-pharmaceutical professional-services

Context

Unit42 states that HelloKitty is a ransomware family that first surfaced at the end of 2020, primarily targeting Windows systems. The malware family got its name due to its use of a Mutex with the same name: HelloKittyMutex. The ransomware samples seem to evolve quickly and frequently, with different versions making use of the .crypted or .kitty file extensions for encrypted files. Some newer samples make use of a Golang packer that ensures the final ransomware code is only loaded in memory, most likely to evade detection by security solutions.

Reports & references

  • Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
  • advintel.io — Enter Karakurt Data Extortion Arm Of Prolific Ransomware Group (report)
  • Palo Alto Unit 42 — Emerging Ransomware Groups (report)
  • blog.bushidotoken.net — Gamer Cheater Hacker Spy (report)
  • blogs.vmware.com — Threat Report Illuminating Volume Shadow Deletion (report)
  • advintel.io — Discontinued The End Of Conti S Brand Marks New Chapter For Cybercrime Landscape (report)
  • esentire.com — Conti Affiliate Exposed New Domain Names Ip Addresses And Email Addresses Uncovered By Esentire (report)
  • blog.malwarebytes.com — Hellokitty When Cyberpunk Met Cy Purr Crime (report)
  • id-ransomware.blogspot.com — Hellokitty Ransomware (report)
  • labs.sentinelone.com — Hellokitty Ransomware Lacks Stealth But Still Strikes Home (report)
  • medium.com — Static Unpacker And Decoder For Hello Kitty Packer 91A3E8844Cb7 (report)
  • twitter.com — 1359167108727332868 (report)
  • bleepingcomputer.com — Hellokitty Ransomware Is Targeting Vulnerable Sonicwall Devices (report)
  • cadosecurity.com — Punk Kitty Ransom Analysing Hellokitty Ransomware Attacks (report)
  • CISA — Aa22 249A (report)
  • CrowdStrike — New Ransomware Variant Uses Golang Packer (report)
  • databreaches.net — Babuk Re Organizes As Payload Bin Offers Its First Leak (report)
  • Mandiant — Unc2447 Sombrat And Fivehands Ransomware Sophisticated Financial Threat (report)
  • ic3.gov — 211029 (report)
  • speartip.com — Fbi Hellokitty Ransomware Adds Ddos To Extortion Arsenal (report)
  • cocomelonc.github.io — Malware Tricks 26 (report)
  • cocomelonc.github.io — Malwild Book (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Hellokitty (report)
  • intrinsec.com — Vice Society Spreads Its Own Ransomware (report)

External references