216.73.217.22

HelloKitty Ransomware Resurfaced

· Published 15/04/2025 19:35 · Modified 16/04/2025 13:21

Export JSON

Essential information

Published
15/04/2025 19:35
Modified
16/04/2025 13:21
Tags
2025-04-15 fivehands hellokitty linux ransomware
Related entities
1 intrusion sets (apt), 10 techniques (mitre), 6 malware, 13 others

Description

The group, active since late 2020, has resurfaced with new variants in 2024 and potentially 2025. Originally forking from DeathRansom, targets Windows and environments, appending .CRYPTED, .CRYPT, or .KITTY extensions to encrypted files. The group has used multiple TOR domains for negotiations and has been linked to high-profile attacks, including CD Projekt Red. Analysis reveals potential connections to China, despite earlier attributions to Ukraine. The employs sophisticated encryption techniques, including RSA-2048 and AES. Recent samples show evolving tactics, with increased focus on system discovery and process termination. has also been utilized by other threat actors, including Vice Society and Lapsus$. The group's continued activity and adaptations suggest ongoing relevance in the landscape.

External references