Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors hellokitty

Description

Unit42 states that HelloKitty is a ransomware family that first surfaced at the end of 2020, primarily targeting Windows systems. The malware family got its name due to its use of a Mutex with the same name: HelloKittyMutex. The ransomware samples seem to evolve quickly and frequently, with different versions making use of the .crypted or .kitty file extensions for encrypted files. Some newer samples make use of a Golang packer that ensures the final ransomware code is only loaded in memory, most likely to evade detection by security solutions. 1 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

HelloKitty is a medium-sophistication ransomware family targeting Windows systems, first identified in late 2020. It encrypts files using extensions like .crypted or .kitty and employs a Golang-based packer to evade detection. The actor's goal is financial gain through rapid campaigns, often targeting small to medium businesses with limited defenses.

Goals & Targeting

HelloKitty targets sectors with high financial reward potential but lacks specific targeting of industries or geographies, suggesting a broad approach to maximize opportunities. The primary goal is financial gain through encrypting files for ransom, typically affecting small to medium organizations.

Enhanced Description

HelloKitty ransomware emerged in late 2020, quickly establishing itself as a formidable threat due to its rapid evolution and effective evasion techniques. Named for its use of the HelloKittyMutex, the malware targets Windows systems, encrypting files and demanding ransoms for decryption keys. Notable for using Golang packers to load code in memory, avoiding detection by security solutions, HelloKitty's operators prioritize financial gain through quick-winnings schemes. The ransomware regularly updates its versions, making it challenging to detect and mitigate. Despite its relatively short tenure, HelloKitty has shown resilience and adaptability.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

52

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Critical Infrastructure

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.