Skip to content

HellCat

Hellcat is a ransomware group that emerged in mid-2024.

Profile source: Mallory opens in a new tab

HellCat

Family profile

Hellcat is a ransomware group that emerged in mid-2024. The provided content states that its main operators are known to be senior members of the BreachForums community, and reporting by Cyfirma and Hudson Rock linked a hacker using the moniker "Rey" to the group. In March 2025, Hellcat was attributed with a significant compromise of Jaguar Land Rover (JLR): the group reportedly used Jira credentials to access JLR’s internal network and leaked 700 internal documents, including development logs, source code, and a large employee dataset containing usernames, email addresses, display names, and time zones. The content consistently associates Hellcat with ransomware activity and with post-compromise behaviors reflected in detection content, including abuse of Windows utilities and living-off-the-land techniques such as netsh, regsvcs, rundll32, PowerShell, BITSAdmin, SQL Server stored procedures, suspicious named pipes, service stopping, process termination bursts, ransomware note creation, network share file-copy activity, and ESXi SSH brute-force activity. High-confidence targeting information in the content is limited, but Hellcat is explicitly tied to enterprise victimization and the JLR intrusion.

Operational record

1
YARA rules
2
Ransom notes
6
Leak sites
0 available

Reported operators

Threat actors

1 named in public reporting
Hellcat

In March, the HELLCAT ransomware group leaked 700 internal documents, purportedly part of a compromise of JLR's internal network using Jira credentials and also included development logs, source code, and a large employee dataset with usernames, email addresses, display names, and time zones, according to an analysis by threat intelligence firm Cyfirma.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.