In March, the HELLCAT ransomware group leaked 700 internal documents, purportedly part of a compromise of JLR's internal network using Jira credentials and also included development logs, source code, and a large employee dataset with usernames, email addresses, display names, and time zones, according to an analysis by threat intelligence firm Cyfirma.
HellCat
Hellcat is a ransomware group that emerged in mid-2024.
Profile source: Mallory opens in a new tabHellCat
Family profile
Hellcat is a ransomware group that emerged in mid-2024. The provided content states that its main operators are known to be senior members of the BreachForums community, and reporting by Cyfirma and Hudson Rock linked a hacker using the moniker "Rey" to the group. In March 2025, Hellcat was attributed with a significant compromise of Jaguar Land Rover (JLR): the group reportedly used Jira credentials to access JLR’s internal network and leaked 700 internal documents, including development logs, source code, and a large employee dataset containing usernames, email addresses, display names, and time zones. The content consistently associates Hellcat with ransomware activity and with post-compromise behaviors reflected in detection content, including abuse of Windows utilities and living-off-the-land techniques such as netsh, regsvcs, rundll32, PowerShell, BITSAdmin, SQL Server stored procedures, suspicious named pipes, service stopping, process termination bursts, ransomware note creation, network share file-copy activity, and ESXi SSH brute-force activity. High-confidence targeting information in the content is limited, but Hellcat is explicitly tied to enterprise victimization and the JLR intrusion.
Operational record
Reported operators