HelloKitty ransomware source code leaked on hacking forum

A threat actor has leaked the complete source code for the first version of the HelloKitty ransomware on a Russian-speaking cybercrime forum claiming to be developing a new, more powerful encryptor.

Cybersecurity researchers 3xp0rt reported that a threat actor that goes online with the moniker ‘kapuchin0’ (and also uses the alias Gookee) has leaked the source code of the HelloKitty ransomware on the XSS forum.

kapuchin0 claims that the leaked code is the first breach of the HelloKitty ransomware.

The leaked archive includes a Microsoft Visual Studio project that can be used to create the HelloKitty ransomware and the related decryptor.

With the help of the popular malware researcher Michael Gillespie, Bleeping Computer confirmed that the source code is legitimate and is related to the first version of the ransomware that was employed in 2020.

The availability of the source in the cybercrime ecosystem can allow threat actors to develop their own version of the Hello Kitty ransomware.

The HelloKitty gang has been active since January 2021. In November 2021, the FBI has published a flash alert warning private organizations of the evolution of the HelloKitty ransomware (aka FiveHands).

According to the alert, the ransomware gang is launching distributed denial-of-service (DDoS) attacks as part of its extortion activities. They target their victims’ websites with DDoS attacks if they refuse to pay the ransom.

The HelloKitty ransomware group implements a double extortion model, stealing sensitive documents from victims before encrypting them. Then the threat actors threaten to leak the stolen data to force the victim into paying the ransom.

The HelloKitty/FiveHands gang is known to demand varying ransom payments in Bitcoin (BTC) and their operators use several techniques to breach the targets’ networks, such as exploiting SonicWall flaws or using compromised credentials.

Image Credits : The Record by Recorded Future

The post HelloKitty ransomware source code leaked on hacking forum first appeared on Cybersafe News.

CyberNews RansomWare