HelloKitty (Windows)
Aliases: KittyCrypt
- First seen
- 2020-12-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Profile updated
- 2026-07-07 13:03:06
Targeted industries: technology-and-telecommunications financial-services healthcare-and-pharmaceutical professional-services
Context
Unit42 states that HelloKitty is a ransomware family that first surfaced at the end of 2020, primarily targeting Windows systems. The malware family got its name due to its use of a Mutex with the same name: HelloKittyMutex. The ransomware samples seem to evolve quickly and frequently, with different versions making use of the .crypted or .kitty file extensions for encrypted files. Some newer samples make use of a Golang packer that ensures the final ransomware code is only loaded in memory, most likely to evade detection by security solutions.
Reports & references
- Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
- advintel.io — Enter Karakurt Data Extortion Arm Of Prolific Ransomware Group (report)
- Palo Alto Unit 42 — Emerging Ransomware Groups (report)
- blog.bushidotoken.net — Gamer Cheater Hacker Spy (report)
- blogs.vmware.com — Threat Report Illuminating Volume Shadow Deletion (report)
- advintel.io — Discontinued The End Of Conti S Brand Marks New Chapter For Cybercrime Landscape (report)
- esentire.com — Conti Affiliate Exposed New Domain Names Ip Addresses And Email Addresses Uncovered By Esentire (report)
- blog.malwarebytes.com — Hellokitty When Cyberpunk Met Cy Purr Crime (report)
- id-ransomware.blogspot.com — Hellokitty Ransomware (report)
- labs.sentinelone.com — Hellokitty Ransomware Lacks Stealth But Still Strikes Home (report)
- medium.com — Static Unpacker And Decoder For Hello Kitty Packer 91A3E8844Cb7 (report)
- twitter.com — 1359167108727332868 (report)
- bleepingcomputer.com — Hellokitty Ransomware Is Targeting Vulnerable Sonicwall Devices (report)
- cadosecurity.com — Punk Kitty Ransom Analysing Hellokitty Ransomware Attacks (report)
- CISA — Aa22 249A (report)
- CrowdStrike — New Ransomware Variant Uses Golang Packer (report)
- databreaches.net — Babuk Re Organizes As Payload Bin Offers Its First Leak (report)
- Mandiant — Unc2447 Sombrat And Fivehands Ransomware Sophisticated Financial Threat (report)
- ic3.gov — 211029 (report)
- speartip.com — Fbi Hellokitty Ransomware Adds Ddos To Extortion Arsenal (report)
- cocomelonc.github.io — Malware Tricks 26 (report)
- cocomelonc.github.io — Malwild Book (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Hellokitty (report)
- intrinsec.com — Vice Society Spreads Its Own Ransomware (report)