HellCat is a ransomware-as-a-service group that formed in Q4 2024 and quickly became notable for high-profile attacks against Schneider Electric, Telefónica, and Israel's Knesset, primarily gaining initial access via stolen Jira credentials harvested by infostealer malware, targeting critical infrastructure and government entities. Known victims: 20 2 ransom note(s) on file
Objectives
Executive Summary
HellCat is a ransomware-as-a-service (RaaS) group that emerged in late 2024. Known for high-profile attacks targeting critical infrastructure, government entities, and major corporations, HellCat operates with medium sophistication and focuses on financial gain through ransomware campaigns. Initial access appears to rely on stolen Jira credentials from infostealer malware.
Goals & Targeting
HellCat appears to target critical infrastructure and government entities in order to maximize the impact of their ransomware campaigns. These sectors are particularly sensitive due to the potential for widespread disruption, which likely increases the group's success rate in negotiating large ransom payments. The choice of high-profile victims suggests a strategic focus on industries with deep pockets and high tolerance for financial losses when operational continuity is at risk.
Enhanced Description
HellCat is a newly emerged RaaS group that quickly gained notoriety due to its aggressive targeting of high-profile victims, including critical infrastructure, government entities, and large corporations such as Schneider Electric, Telefónica, and Israel's Knesset. The group primarily achieves initial access through the use of stolen Jira credentials, obtained via infostealer malware deployed in their attack chain. Once inside target networks, HellCat deploys ransomware to encrypt systems and extort payment from victims. Despite being a relatively new entry in the cybercrime landscape as of Q4 2024, HellCat has demonstrated both technical capability and strategic focus on high-value targets within critical sectors. The group's operational timeline extends through at least early 2025, with ongoing activity observed up to April of that year.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
HellCat's campaigns exhibit a focus on high-profile, high-impact targets. The group's operational pattern involves rapid deployment of infostealer malware to harvest credentials, followed by internal network traversal and ransomware encryption. Notable past operations include attacks against Schneider Electric and other critical infrastructure entities, suggesting an appetite for disrupting essential services. The relatively short time since their emergence indicates a potentially agile and adaptable threat group.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The data on HellCat is limited but growing, with confirmed attacks against major organizations. The group's TTPs are observable through their use of infostealers and ransomware deployment patterns. Gaps include specific malware toolset identification and exact geographic targeting scope outside Europe.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics