Ransomware Group intelligence
Hellokitty
ActiveTrack Hellokitty with 0 published victims and 1 known leak locations in a single intelligence view.
Overview
Hellokitty is tracked by Breach House as a ransomware group with 0 published victims.
The group is tracked across multiple victim records in the Breach House dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 8h ago | 3r6n77mpe737w4sbxxxrpc5phbluv6xhtdl5ujpnlvmck5tc7blq2rqd.onion |
Top Activity Sectors
No sector intelligence available.
Typical Attacks (6)
▼How Hellokitty typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via HELLOKITTY.
-
T1047 Windows Management Instrumentation Execution
What they do: HELLOKITTY can use WMI to delete volume shadow copies.
What that means: Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads.
-
T1057 Process Discovery Discovery
What they do: HELLOKITTY can search for specific processes to terminate.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1135 Network Share Discovery Discovery
What they do: HELLOKITTY has the ability to enumerate network resources.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1680 Local Storage Discovery Discovery
What they do: HELLOKITTY can enumerate logical drives on a target system.
What that means: Adversaries may enumerate local drives, disks, and/or volumes and their attributes like total or free space and volume serial number.
-
T1486 Data Encrypted for Impact Impact
What they do: HELLOKITTY can use an embedded RSA-2048 public key to encrypt victim data for ransom.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: HELLOKITTY can delete volume shadow copies on compromised hosts.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Crypto Wallets (1)
▼| Address | Chain | Received (USD) | Payments |
|---|---|---|---|
bc1ql5f3m75qx3ueu2pz5eeveyqsw6pdjs3ufk8r20 |
bitcoin | $1,072,689 | 2 |
Crowdsourced payment data from Ransomwhere, licensed CC BY 4.0. Figures are what has been reported and attributed to this family, not a confirmed total. Cite as: Cable, Jack. (2024). Ransomwhere: A Crowdsourced Ransomware Payment Dataset (1.1.0) [Data set]. Zenodo. https://doi.org/10.5281/zenodo.6512122
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
[File_Name].README_TO_RESTORE
Hello [snip], Unfortunately, your files were encrypted, and more than 200 GB of your critical date was leaked from your File, DEV and SQL servers (Administration and Finance, Direzione, Legal, HR, Risorse umane). For a more detailed list of documents, please contact us and we will send you the samples we have. We are also ready to help you recover your files, prevent the spread of leaks, as well as help solve problems in your IT infrastructure that were the cause of the current situation, so that this does not happen again in the future. Just contact support using the following methods and we will decrypt one non-important file for free to convince you of our honesty. Contact us method below: Use TOR Browser: http://gunyhng6pabzcurl7ipx2pbmjxpvqnu6mxf2h3vdeenam34inj4ndryd.onion/[snip] ************************************************ [binary_data]
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (0)
Search, filter and paginate the victim timeline for Hellokitty.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|