Unit42 states that HelloKitty is a ransomware family that first surfaced at the end of 2020, primarily targeting Windows systems. The malware family got its name due to its use of a Mutex with the same name: HelloKittyMutex. The ransomware samples seem to evolve quickly and frequently, with different versions making use of the .crypted or .kitty file extensions for encrypted files. Some newer samples make use of a Golang packer that ensures the final ransomware code is only loaded in memory, most likely to evade detection by security solutions. 1 ransom note(s) on file
Objectives
Executive Summary
HelloKitty is a medium-sophistication ransomware family targeting Windows systems, first identified in late 2020. It encrypts files using extensions like .crypted or .kitty and employs a Golang-based packer to evade detection. The actor's goal is financial gain through rapid campaigns, often targeting small to medium businesses with limited defenses.
Goals & Targeting
HelloKitty targets sectors with high financial reward potential but lacks specific targeting of industries or geographies, suggesting a broad approach to maximize opportunities. The primary goal is financial gain through encrypting files for ransom, typically affecting small to medium organizations.
Enhanced Description
HelloKitty ransomware emerged in late 2020, quickly establishing itself as a formidable threat due to its rapid evolution and effective evasion techniques. Named for its use of the HelloKittyMutex, the malware targets Windows systems, encrypting files and demanding ransoms for decryption keys. Notable for using Golang packers to load code in memory, avoiding detection by security solutions, HelloKitty's operators prioritize financial gain through quick-winnings schemes. The ransomware regularly updates its versions, making it challenging to detect and mitigate. Despite its relatively short tenure, HelloKitty has shown resilience and adaptability.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
52
IOCs
0
Observed Data
0
Tactics