ATT&CKSoftwareHELLOKITTY

HELLOKITTY

S0617

Malware.View on attack.mitre.org

About this malware

HELLOKITTY is a ransomware written in C++ that shares similar code structure and functionality with DEATHRANSOM and FIVEHANDS. HELLOKITTY has been used since at least 2020, targets have included a Polish video game developer and a Brazilian electric power company.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1047
Windows Management Instrumentation

HELLOKITTY can use WMI to delete volume shadow copies.

T1057
Process Discovery

HELLOKITTY can search for specific processes to terminate.

T1135
Network Share Discovery

HELLOKITTY has the ability to enumerate network resources.

T1486
Data Encrypted for Impact

HELLOKITTY can use an embedded RSA-2048 public key to encrypt victim data for ransom.

T1490
Inhibit System Recovery

HELLOKITTY can delete volume shadow copies on compromised hosts.

T1680
Local Storage Discovery

HELLOKITTY can enumerate logical drives on a target system.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. FireEye FiveHands April 2021 Open source
    McLellan, T. and Moore, J. et al. (2021, April 29). UNC2447 SOMBRAT and FIVEHANDS Ransomware: A Sophisticated Financial Threat. Retrieved June 2, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.