Malware.View on attack.mitre.org
HELLOKITTY is a ransomware written in C++ that shares similar code structure and functionality with DEATHRANSOM and FIVEHANDS. HELLOKITTY has been used since at least 2020, targets have included a Polish video game developer and a Brazilian electric power company.
| Technique | Procedure example |
|---|---|
| T1047 Windows Management Instrumentation |
HELLOKITTY can use WMI to delete volume shadow copies. |
| T1057 Process Discovery |
HELLOKITTY can search for specific processes to terminate. |
| T1135 Network Share Discovery |
HELLOKITTY has the ability to enumerate network resources. |
| T1486 Data Encrypted for Impact |
HELLOKITTY can use an embedded RSA-2048 public key to encrypt victim data for ransom. |
| T1490 Inhibit System Recovery |
HELLOKITTY can delete volume shadow copies on compromised hosts. |
| T1680 Local Storage Discovery |
HELLOKITTY can enumerate logical drives on a target system. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.