HelloKitty samples were retrieved from their campaigns targeting Linux systems at the end of 2021... Oldest samples from 2021 are HelloKitty ransomware for Linux (ELF binaries), and most recent ones (June 2022) are Zeppelin ransomware.
HELLOKITTY
HelloKitty is a human-operated ransomware family first observed in November 2020 that targets Windows systems, Linux servers, and VMware ESXi virtualization infrastructure.
HELLOKITTY
Family profile
HelloKitty is a human-operated ransomware family first observed in November 2020 that targets Windows systems, Linux servers, and VMware ESXi virtualization infrastructure. It encrypts victim files and leaves customized ransom notes demanding payment for decryption, with negotiations conducted through Tor-based portals or email. Variants use hybrid encryption schemes, including AES with RSA or NTRU. Implementations include C++ variants and a Go-based variant observed in May 2021.
Before encryption, HelloKitty discovers running processes and network resources and terminates services and applications that could interfere with file access. Windows variants target enterprise applications and backup software, using Windows utilities, WMI, and the Restart Manager API to identify and terminate processes. Some variants delete volume shadow copies to hinder recovery. Its ESXi-targeting encryptors, publicly identified in July 2021, enumerate running virtual machines and attempt to stop them through the esxcli management utility, escalating from graceful to forced termination before encrypting virtual disks, metadata, and snapshots. This enables a single compromised virtualization host to affect multiple business systems.
HelloKitty has been delivered through phishing emails and secondary malware infections. Associated operators have also exploited vulnerabilities in internet-facing services, including SonicWall CVE-2019-7481 and Apache ActiveMQ CVE-2023-46604. Vice Society deployed HelloKitty Linux binaries in campaigns in late 2021. Notable victims include game developer CD Projekt Red and Brazilian energy company CEMIG. HelloKitty-associated intrusions have combined encryption with data theft and threats to disclose or sell stolen information; these campaign-level activities do not establish that the encryptor itself performs exfiltration.
Capabilities
- Defense Evasion
- Extortion
- Reconnaissance
Samples
Recent samples
1 sandbox sample in the Derp library, newest 1 shown
Reported operators
Threat actors
5 named in public reportingIn July 2021 an encryptor that targeted explicitly VMware ESXi systems was discovered.
This activity group also developed and deployed the FiveHands and HelloKitty ransomware payloads and often gained access to an organization via DEV-0193’s BazaLoader infrastructure.
A threat actor has leaked the complete source code for the first version of the HelloKitty ransomware on a Russian-speaking hacking forum, claiming to be developing a new, more powerful encryptor.
HELLOKITTY ransomware—used to target Polish video game developer CD Projekt Red—is reportedly built from DEATHRANSOM.
Exploited software
Vulnerabilities linked to HELLOKITTY
4 CVEsMITRE ATT&CK
HELLOKITTY in ATT&CK
33 distinct techniquesTechniques
33 techniquesReporting
Research mentioning HELLOKITTY
Multi-Platform SMAUG RaaS Aims To See Off Competitors - SentinelLabs
SMAUG is a ransomware-as-a-service (RaaS) operation that advertises 64-bit payloads for Windows, Linux, and macOS, positioning itself as a multi-platform option for affiliates. The service reportedly charges a 20% affiliate fee plus a 0.2 BTC registration fee, and provides a web-based campaign builder, customizable ransom demands, offline encryption, and a "Company Mode" that allows a single decryption key to unlock multiple systems inside one targeted organization. Victims are directed to a Tor-based payment portal, while operators reportedly offer automated support for both affiliates and victims and bar attacks against CIS countries. On Windows, SMAUG uses obfuscated Go binaries that gather system details and stored browser credentials, establish persistence through Registry Run Keys consistent with MITRE ATT&CK T1547.001, and then encrypt files for impact using AES-256 with keys protected by RSA-2048, aligning with T1486 Data Encrypted for Impact tradecraft. The combination of credential collection, registry-based autostart, and hybrid cryptography reflects a mature ransomware model designed to support repeatable intrusions and broad enterprise targeting across multiple operating systems.
VPN Appliance Forensics - Compass Security Blog
CISA warned that threat actors are actively exploiting CVE-2019-7481 in SonicWall Secure Mobile Access (SMA) 100 series and Secure Remote Access (SRA) appliances that remain on end-of-life firmware, with intrusions leading to targeted ransomware attacks. SonicWall issued an urgent notice telling customers to upgrade to supported firmware immediately or disconnect affected appliances, underscoring that patched but unsupported devices remain exposed if they have not been properly updated. Reporting linked the campaign to multiple eCrime actors, including HelloKitty, and CrowdStrike identified the SonicWall flaw as a key access vector being leveraged in the wild. The activity fits a broader pattern of ransomware groups abusing SonicWall edge devices for initial access, with prior exploitation by actors associated with Babuk, UNC2447, and UNC2682 across VPN and email security products.
HelloKitty Ransomware Lacks Stealth, But Still Strikes Home - SentinelLabs
HelloKitty ransomware emerged as a targeted extortion threat that gained broad attention after being linked to the attack on game studio CD Projekt Red. Researchers described the malware as less stealthy than major families such as Ryuk, REvil, and Conti, but still highly disruptive, with operators using Tor-based payment portals, customized ransom notes, and in some cases auctioning stolen data on underground forums. The family has also been referred to as Kitty, and reporting tied it to later variants and related offshoots including FiveHands, Kitty Go, Kitty Linux, Vice Society, and Boombye.