logo

HELLCAT Ransomware Group Strikes Again: Four New Victims Breached via Jira Credentials from Infostealer Logs

ID: fb74e7ad-edd0-5a18-a333-529bffa9f1dc

STIX ID: report--fb74e7ad-edd0-5a18-a333-529bffa9f1dc

Feed Name: infostealers.com

Threat Score
75/100

Date Published: 2025-04-05

Date Updated: 2026-06-07

Author: InfoStealers

...
...

Hudson Rock reports that the HellCat ransomware group recently compromised Atlassian Jira instances at HighWire Press, Asseco Poland, Racami, and LeoVegas by leveraging Jira credentials harvested from victims' machines by infostealer malware; the group exfiltrated sensitive data, published breach proofs with countdown timers on its leak site, and issued extortion demands. The article links these attacks to infostealer logs in Hudson Rock’s database, documents HellCat’s repeated use of this playbook, and recommends detection and mitigation steps such as EDR monitoring, immediate credential resets, MFA for Jira, network segmentation, and employee training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.