Skip to content

HELLOKITTY

HelloKitty, also known as Kitty, is a human-operated ransomware family first observed in late 2020.

Profile source: Mallory opens in a new tab

HELLOKITTY

Family profile

HelloKitty, also known as Kitty, is a human-operated ransomware family first observed in late 2020. It encrypts victim data and presents customized ransom notes that direct victims to Tor-based negotiation and payment portals. Windows variants have used AES encryption with RSA-2048 or NTRU public-key protection, while Linux variants have used AES-256 with ECDH-based key protection. Variants have been implemented in C++ and Go.

HelloKitty disables processes and services that could impede encryption, including enterprise application, database, messaging, backup, and web-server components. It can enumerate running processes and network resources, terminate selected processes and services, and delete shadow copies. Windows samples use built-in utilities, WMI, and the Windows Restart Manager API to identify and stop processes. The family uses a mutex to prevent concurrent execution.

HelloKitty has Windows and Linux encryptors, including Linux ELF payloads designed for VMware ESXi hosts. Its ESXi-focused variant uses the ESXi management interface to enumerate running virtual machines and attempts graceful, hard, and forced VM shutdown before encrypting virtual-disk, metadata, and snapshot files. Targeting hypervisors enables a single ransomware deployment to disrupt multiple virtualized workloads.

HelloKitty was provisionally linked to the February 2021 ransomware attack against CD Projekt Red, where attackers encrypted systems and claimed theft of game source code and internal business data. HelloKitty-associated activity has also been linked to exploitation of vulnerable SonicWall remote-access appliances and Apache ActiveMQ systems. The family has been used in campaigns against organizations globally, including enterprises and virtualization infrastructure. Phishing and secondary deployment following other malware infections have also been reported as delivery methods.

Capabilities

  • Defense Evasion
  • Extortion
  • Initial Access
  • Reconnaissance

Operational record

54
Indicators
1
YARA rules
1
Ransom notes
1
Leak sites
0 available

Published indicators

Md5

52 total
  • 50363f811d630e8e3ceb84f6f3db066e
  • 28c5c992809fecdc82509dab19c0d90a
  • db804c3f55c5d09dace40c76c99cab52
  • ba35a80338fbf197a323f6fe960bf7cb
  • e333299d9f7e4c064746e177c84bb5c8
  • 87b418a1d8eaf648b6338af20407abbb
  • bd0802f8a9a71336607d5c9241db31d9
  • 06ce6cd8bde756265f95fcf4eecadbe9
  • 7ffaaaef5bcaf94756352b1fc866ef3d
  • 3342dc0e3aac48664341cd2fed82d8f0

Reported operators

Threat actors

5 named in public reporting
Vanilla Tempest

HelloKitty samples were retrieved from their campaigns targeting Linux systems at the end of 2021... Oldest samples from 2021 are HelloKitty ransomware for Linux (ELF binaries), and most recent ones (June 2022) are Zeppelin ransomware.

ViceSociety

In July 2021 an encryptor that targeted explicitly VMware ESXi systems was discovered.

DEV-0230

This activity group also developed and deployed the FiveHands and HelloKitty ransomware payloads and often gained access to an organization via DEV-0193’s BazaLoader infrastructure.

Gookee

A threat actor has leaked the complete source code for the first version of the HelloKitty ransomware on a Russian-speaking hacking forum, claiming to be developing a new, more powerful encryptor.

UNC2447

HELLOKITTY ransomware—used to target Polish video game developer CD Projekt Red—is reportedly built from DEATHRANSOM.

Exploited software

Vulnerabilities linked to HELLOKITTY

4 CVEs

MITRE ATT&CK

HELLOKITTY in ATT&CK

33 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.