logo

Emerging Threat Actor Hellcat Exemplifies Continued Innovation in Ransomware TPPs

ID: ca69b8eb-e8ae-58f1-b040-8555bc374bdd

STIX ID: report--ca69b8eb-e8ae-58f1-b040-8555bc374bdd

Feed Name: Halcyon Blog

Threat Score
78/100

Date Published: 2025-04-10

Date Updated: 2026-04-28

...
...

Hellcat is a rapidly evolving Ransomware-as-a-Service strain active since mid-2024 that targets critical sectors (government, education, energy) and employs advanced tradecraft — including spear phishing and zero-day exploitation for access, multi-stage PowerShell infection chains, reflective in-memory code loading, AMSI bypasses, SliverC2 for persistent access, and living‑off‑the‑land tools — to deliver high-impact double‑extortion and operational disruption.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.