Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors hellcat

Description

HellCat is a ransomware-as-a-service group that formed in Q4 2024 and quickly became notable for high-profile attacks against Schneider Electric, Telefónica, and Israel's Knesset, primarily gaining initial access via stolen Jira credentials harvested by infostealer malware, targeting critical infrastructure and government entities. Known victims: 20 2 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

HellCat is a ransomware-as-a-service (RaaS) group that emerged in late 2024. Known for high-profile attacks targeting critical infrastructure, government entities, and major corporations, HellCat operates with medium sophistication and focuses on financial gain through ransomware campaigns. Initial access appears to rely on stolen Jira credentials from infostealer malware.

Goals & Targeting

HellCat appears to target critical infrastructure and government entities in order to maximize the impact of their ransomware campaigns. These sectors are particularly sensitive due to the potential for widespread disruption, which likely increases the group's success rate in negotiating large ransom payments. The choice of high-profile victims suggests a strategic focus on industries with deep pockets and high tolerance for financial losses when operational continuity is at risk.

Enhanced Description

HellCat is a newly emerged RaaS group that quickly gained notoriety due to its aggressive targeting of high-profile victims, including critical infrastructure, government entities, and large corporations such as Schneider Electric, Telefónica, and Israel's Knesset. The group primarily achieves initial access through the use of stolen Jira credentials, obtained via infostealer malware deployed in their attack chain. Once inside target networks, HellCat deploys ransomware to encrypt systems and extort payment from victims. Despite being a relatively new entry in the cybercrime landscape as of Q4 2024, HellCat has demonstrated both technical capability and strategic focus on high-value targets within critical sectors. The group's operational timeline extends through at least early 2025, with ongoing activity observed up to April of that year.

Key Capabilities

  • Ransomware deployment
  • Infostealer malware use
  • Credential harvesting (Jira credentials)
  • Network infiltration via stolen credentials
  • Targeting critical infrastructure

MITRE ATT&CK Tactics

Initial Access
Credential Access
Persistence
Defense Evasion

ATT&CK Techniques

T1059.003
T1055
T1566.001

Software / Tooling

Infostealer malware (possibly custom or known families)
Custom ransomware
Lateral movement tools

Campaigns & Victims

HellCat's campaigns exhibit a focus on high-profile, high-impact targets. The group's operational pattern involves rapid deployment of infostealer malware to harvest credentials, followed by internal network traversal and ransomware encryption. Notable past operations include attacks against Schneider Electric and other critical infrastructure entities, suggesting an appetite for disrupting essential services. The relatively short time since their emergence indicates a potentially agile and adaptable threat group.

IOC Patterns

  • Spear-phishing with stolen Jira credential access
  • Infostealer malware activity in pre-attack phase
  • Ransomware deployment to critical systems

Recommended Actions

  • Implement multi-factor authentication for Jira and other critical systems.
  • Monitor network traffic for signs of lateral movement or infostealing activity.
  • Regularly patch and secure internal systems to prevent credential harvesting.
  • Conduct regular phishing simulations to test email security resilience.

Suggested Tags

Ransomware
Critical Infrastructure Targeting
High-impact Attacks

Confidence Assessment

The data on HellCat is limited but growing, with confirmed attacks against major organizations. The group's TTPs are observable through their use of infostealers and ransomware deployment patterns. Gaps include specific malware toolset identification and exact geographic targeting scope outside Europe.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Critical Infrastructure
Government Targeting
Critical Infrastructure Targeting
High-impact Attacks

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Oct 25, 2024
Last Seen
Apr 7, 2025
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.