Emerging Threat Actor Hellcat Exemplifies Continued Innovation in Ransomware TPPs
ID: ca69b8eb-e8ae-58f1-b040-8555bc374bdd
STIX ID: report--ca69b8eb-e8ae-58f1-b040-8555bc374bdd
Feed Name: Halcyon Blog
Threat Score
Hellcat is a rapidly evolving Ransomware-as-a-Service strain active since mid-2024 that targets critical sectors (government, education, energy) and employs advanced tradecraft — including spear phishing and zero-day exploitation for access, multi-stage PowerShell infection chains, reflective in-memory code loading, AMSI bypasses, SliverC2 for persistent access, and living‑off‑the‑land tools — to deliver high-impact double‑extortion and operational disruption.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
