TF-MAL-elf.hellokitty
📛 Threat Title
Malware family: HelloKitty
Description
ThreatFox malware family `elf.hellokitty`. Printable name: HelloKitty.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.hellokitty
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.hellokitty
IOC database
- Type
- domain
- Value
elf.hellokitty- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Extracted from Threat TF-MAL-elf.hellokitty
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.hellokitty
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:community.fortinet.com
Threat Coverage: How FortiEDR protects against HelloKitty /TellYouThePass Ransomware Introduction In October 2023, the source code for a ransomware family dubbed 'HelloKitty' was leaked on the XSS forum [1]. This variant is suspected to be a later iteration of the FiveHands ransomware [2] based on shared infrastructure and code similarity.
-
web:cybersecuritynews.com
The recently disclosed Apache ActiveMQ remote code execution (RCE) flaw, CVE-2023-46604 is being exploited to spread ransomware binaries on target systems and demand a ransom from the victim organizations. Based on the evidence and the ransom note, Rapid7 experts have linked the activity to the HelloKitty ransomware family , whose source code was made public on a forum in early October. CVE ...
-
web:github.com
Decoded HelloKitty Ransomware. Contribute to cado-security/ hellokitty -ransomware development by creating an account on GitHub.
-
web:mssplab.github.io
Malware source code investigation: HelloKitty - part 2. NTRUEncrypt 9 minute read HelloKitty ransomware represents a sophisticated strain of malicious software strategically designed for targeted attacks, demonstrating an evolved and nuanced approach within the realm of cybersecurity threats.
-
web:prevent-ransomware.com
Kraken ransomware—emerging from the remnants of HelloKitty—uses cross-platform encryption and stealthy tactics.
-
web:threatfox.abuse.ch
A malware sample can be associated with only one malware family . The page below gives you an overview on indicators of compromise associated with win. hellokitty .
-
web:www.bleepingcomputer.com
A remote code execution (RCE) flaw impacting Apache ActiveMQ has been under active exploitation by threat actors who use HelloKitty ransomware payloads.
-
web:www.ransomlook.io
Description HelloKitty is a ransomware family first observed in November 2020, named after a string found in its binary. It operates as a human-operated, big-game hunting ransomware, manually deployed after network intrusion and reconnaissance. HelloKitty uses a double-extortion model—encrypting files and threatening to leak stolen data on a Tor-based site. The malware encrypts files using ...
-
web:www.sentinelone.com
Hello Kitty ransomware may sound cute but hits hard with file encryption. Learn its tricky infection path, who it targets, and how to stop it.
-
web:www.thodex.com
Combatting threats like Hello Kitty ransomware requires proactive and comprehensive mitigation strategies. Educating employees on the risks associated with ransomware and how to avoid phishing attempts is the first line of defense.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.