HelloKitty — Ransomware Profile
HelloKitty was a hands-on-keyboard, double-extortion ransomware operation that BleepingComputer dates to a November 2020 launch. Mandiant documented the family in April 2021, relaying that it was reportedly built from the earlier DEATHRANSOM codebase, that it was the strain used against Polish games studio CD Projekt Red, and that deployments appeared to shift to a rewritten encryptor called FIVEHANDS from around January 2021 under what it assessed may have been a single affiliate program; Mandiant also cautioned that one ransomware family can be shared between different crews through underground affiliate programs, which is why the family is not interchangeable with the UNC2447 intrusion set that Mandiant observed deploying FIVEHANDS. An FBI FLASH advisory of 28 October 2021, coordinated with DHS/CISA, tracked the activity jointly as "Hello Kitty/FiveHands" and said the operators broke in using stolen credentials or known SonicWall product flaws, naming CVE-2021-20016, CVE-2021-20021, CVE-2021-20022 and CVE-2021-20023, then escalated against slow or non-paying victims by launching DDoS attacks against their public-facing websites. By July 2021 researchers had also found Linux ELF64 builds that shut down and encrypted virtual machines on VMware ESXi hosts. The operation ended in October 2023, when an actor using the handles "kapuchin0" and "Gookee", who claims to have created it, published the builder and full source code on a Russian-speaking hacking forum; in April 2024 the same actor announced a rebrand to "HelloGookie" and dumped old decryption keys alongside data stolen from CD Projekt and Cisco. Its tracked leak-site infrastructure is now offline with no recorded posts, and no public source establishes where the operators are based.Also tracked as
FiveHands, HelloGookie
Vendor research
- UNC2447 SOMBRAT and FIVEHANDS Ransomware: A Sophisticated Financial Threat Mandiant (Google Cloud Threat Intelligence)
- FLASH CU-000154-MW: Tactics, Techniques, and Indicators of Compromise Associated with Hello Kitty/FiveHands Ransomware FBI (coordinated with DHS/CISA)
- Analysis Report AR21-126A: FiveHands Ransomware CISA
- HelloKitty ransomware source code leaked on hacking forum BleepingComputer