logo

Cato CTRL Threat Research: Unmasking Hellcat – Not Your Average Ransomware Gang

ID: f14e8cc8-dd03-5415-96f8-cafa12edf5b2

STIX ID: report--f14e8cc8-dd03-5415-96f8-cafa12edf5b2

Feed Name: Cato Networks

Threat Score
78/100

Date Published: 2025-01-28

Date Updated: 2026-07-23

Author: Etay Maor

...
...

**Executive Summary:** Hellcat is a newly observed RaaS ransomware gang active in late 2024 that conducts double-extortion attacks and data leaks against government, education, and energy sectors; the report documents several incidents (including Schneider Electric with ~40GB exfiltrated and multiple root-access sales), describes TTPs such as zero-day exploitation and privilege escalation, and recommends defenses using the Cato SASE security stack.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.