logo

HELLOKITTY RANSOMWARE — RESURFACED?

ID: 131699f2-8c87-558c-a4a2-cfcf3ef7c011

STIX ID: report--131699f2-8c87-558c-a4a2-cfcf3ef7c011

Feed Name: THE RAVEN FILE

Threat Score
70/100

Date Published: 2025-04-10

Date Updated: 2026-04-19

Author: RakeshKrish

...
...

**HelloKitty ransomware research summary**: This report presents a year-long technical analysis of HelloKitty (aka FiveHands/derivatives) covering 2020–2024 samples, encryption internals (embedded RSA-2048/NTRU, Salsa20/AES flows), observed TTPs (shadow copy deletion, process termination/injection, persistence via WMI, privilege escalation), victim list (notable victims including CD Projekt Red), TOR negotiation domains, sample IOCs (MD5s, onion addresses, IPs), and discussion of attribution (conflicting signals pointing to Ukraine and China).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.