s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.hellokitty

📛 Threat Title

Malware family: HelloKitty

Category: HelloKitty First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.hellokitty`. Printable name: HelloKitty.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.hellokitty VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.hellokitty

IOC database

Type
domain
Value
elf.hellokitty
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Extracted from Threat TF-MAL-elf.hellokitty

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.hellokitty

References (1)

Remediations (10)

  • web:community.fortinet.com

    Threat Coverage: How FortiEDR protects against HelloKitty /TellYouThePass Ransomware Introduction In October 2023, the source code for a ransomware family dubbed 'HelloKitty' was leaked on the XSS forum [1]. This variant is suspected to be a later iteration of the FiveHands ransomware [2] based on shared infrastructure and code similarity.

  • web:cybersecuritynews.com

    The recently disclosed Apache ActiveMQ remote code execution (RCE) flaw, CVE-2023-46604 is being exploited to spread ransomware binaries on target systems and demand a ransom from the victim organizations. Based on the evidence and the ransom note, Rapid7 experts have linked the activity to the HelloKitty ransomware family , whose source code was made public on a forum in early October. CVE ...

  • web:github.com

    Decoded HelloKitty Ransomware. Contribute to cado-security/ hellokitty -ransomware development by creating an account on GitHub.

  • web:mssplab.github.io

    Malware source code investigation: HelloKitty - part 2. NTRUEncrypt 9 minute read HelloKitty ransomware represents a sophisticated strain of malicious software strategically designed for targeted attacks, demonstrating an evolved and nuanced approach within the realm of cybersecurity threats.

  • web:prevent-ransomware.com

    Kraken ransomware—emerging from the remnants of HelloKitty—uses cross-platform encryption and stealthy tactics.

  • web:threatfox.abuse.ch

    A malware sample can be associated with only one malware family . The page below gives you an overview on indicators of compromise associated with win. hellokitty .

  • web:www.bleepingcomputer.com

    A remote code execution (RCE) flaw impacting Apache ActiveMQ has been under active exploitation by threat actors who use HelloKitty ransomware payloads.

  • web:www.ransomlook.io

    Description HelloKitty is a ransomware family first observed in November 2020, named after a string found in its binary. It operates as a human-operated, big-game hunting ransomware, manually deployed after network intrusion and reconnaissance. HelloKitty uses a double-extortion model—encrypting files and threatening to leak stolen data on a Tor-based site. The malware encrypts files using ...

  • web:www.sentinelone.com

    Hello Kitty ransomware may sound cute but hits hard with file encryption. Learn its tricky infection path, who it targets, and how to stop it.

  • web:www.thodex.com

    Combatting threats like Hello Kitty ransomware requires proactive and comprehensive mitigation strategies. Educating employees on the risks associated with ransomware and how to avoid phishing attempts is the first line of defense.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.