Skip to main content
Ransomware Group

Hellokitty

Unit42 states that HelloKitty is a ransomware family that first surfaced at the end of 2020, primarily targeting Windows systems. The malware family got its name due to its use of a Mutex with the same name: HelloKittyMutex. The ransomware samples seem to evolve quickly and frequently, with different versions making use of the .crypted or .kitty file extensions for encrypted files. Some newer samples make use of a Golang packer that ensures the final ransomware code is only loaded in memory, most likely to evade detection by security solutions.

Known victims0

Threat Level

LOW

Known Infrastructure

The following Tor hidden services have been associated with this group:

  • News

Warning: These are malicious sites. Do not visit without proper security measures.

0

Check If You’re Affected

Search our database to see if your organization appears in Hellokitty’s victim list.

Try it nowFree⌘K
Try

risk score · threat categories · sources · age · confidence — in one request