LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0617: HELLOKITTY

MITRE ATT&CK S0617: HELLOKITTY Malware details for Windows, with detection guidance, relationships and mapped CVEs.

EnterpriseS0617MalwareObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

HELLOKITTY matters because it is Windows ransomware associated in ATT&CK with discovery, WMI-based execution, encryption for impact, and actions that can inhibit recovery. For leaders, the practical issue is not just malware identification; it is whether the organization can detect pre-encryption discovery, protect recovery options, and restore operations if shared drives or business-critical Windows systems are encrypted.

Executive priority

Prioritize this as an operational resilience and incident readiness concern. The ATT&CK relationships point to behaviors that affect business continuity: identifying processes and storage, discovering network shares, executing through Windows Management Instrumentation, encrypting data, and weakening recovery. Executives should ask whether backup and restore evidence is current, whether SOC teams can see WMI and discovery activity on Windows endpoints, and whether ransomware response playbooks include decisions for isolating affected systems, validating backups, and communicating operational impact.

Technical view

For SOC, detection engineering, and IR teams, validate coverage around the related techniques: T1047 Windows Management Instrumentation, T1057 Process Discovery, T1135 Network Share Discovery, T1680 Local Storage Discovery, T1486 Data Encrypted for Impact, and T1490 Inhibit System Recovery. Because the official ATT&CK entry does not provide malware-specific detection guidance, focus on behavior-based monitoring for Windows ransomware tradecraft rather than HELLOKITTY-specific indicators. Confirm visibility into WMI execution, process enumeration, share enumeration, storage/volume discovery, abnormal file encryption patterns, and attempts to disable or remove recovery mechanisms.

Likely telemetry

  • Windows endpoint process creation and command-line telemetry
  • WMI activity and remote/local WMI execution logs
  • Windows event logs relevant to service, process, and administrative activity
  • Network share access and SMB-related audit telemetry
  • File system activity showing high-volume file modification or encryption-like behavior

Detection direction

  • Validate that ransomware detections do not rely only on final encryption behavior; discovery of processes, shares, and storage may provide earlier warning.
  • Tune detections for unusual WMI execution patterns, especially when paired with discovery commands or broad access to network shares.
  • Correlate process discovery, network share discovery, and local storage discovery with subsequent file modification spikes or recovery-inhibition events.
  • Review false positives from legitimate administration tools, backup software, inventory scanners, and IT automation that may use WMI or enumerate systems.
  • Ensure detection content is scoped to the supported malware platform from the ATT&CK object: Windows.

Mitigation priorities

  • Confirm resilient, tested, and access-controlled backups, including protection against deletion or tampering with recovery mechanisms.
  • Restrict and monitor administrative use of WMI, especially remote execution paths and privileged accounts.
  • Harden access to network shares using least privilege and audit high-risk shared locations that could amplify ransomware impact.
  • Segment critical Windows systems and business-critical file repositories to reduce blast radius.
  • Maintain incident response procedures for rapid isolation, backup validation, restoration prioritization, and executive decision-making during ransomware events.
Additional notes and limits

The official ATT&CK description identifies HELLOKITTY as C++ ransomware with similar code structure and functionality to DEATHRANSOM and FIVEHANDS, used since at least 2020, with cited targets including a Polish video game developer and a Brazilian electric power company. The most useful defensive value comes from the related behaviors: WMI execution, discovery of processes, shares and local storage, data encryption, and inhibition of recovery.

The supplied ATT&CK object has no official detection text, no listed tactics on the malware object itself, no aliases, and only Windows as the malware platform. Related techniques include broader platform lists, but those should not be interpreted as HELLOKITTY platform support. Local telemetry, architecture, backup design, and administrative baselines are required to determine actual exposure and detection coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

HELLOKITTY

No official description is available in the imported ATT&CK source object.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

6 rows
DomainIDNameRelationship / procedure
EnterpriseT1486Data Encrypted for ImpactThis object uses Data Encrypted for Impact.
EnterpriseT1490Inhibit System RecoveryThis object uses Inhibit System Recovery.
EnterpriseT1135Network Share DiscoveryThis object uses Network Share Discovery.
EnterpriseT1047Windows Management InstrumentationThis object uses Windows Management Instrumentation.
EnterpriseT1680Local Storage DiscoveryThis object uses Local Storage Discovery.
EnterpriseT1057Process DiscoveryThis object uses Process Discovery.
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.0
Created
Modified
Raw hash
d9842bc05cbc86d5...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.0Current bundled9842bc05cbc…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    FireEye FiveHands April 2021

    McLellan, T. and Moore, J. et al. (2021, April 29). UNC2447 SOMBRAT and FIVEHANDS Ransomware: A Sophisticated Financial Threat. Retrieved June 2, 2021.

    Open source URL
  2. [2]
    FireEye FiveHands April 2021

    McLellan, T. and Moore, J. et al. (2021, April 29). UNC2447 SOMBRAT and FIVEHANDS Ransomware: A Sophisticated Financial Threat. Retrieved June 2, 2021.

    Open source URL
  3. [3]
    FireEye FiveHands April 2021

    McLellan, T. and Moore, J. et al. (2021, April 29). UNC2447 SOMBRAT and FIVEHANDS Ransomware: A Sophisticated Financial Threat. Retrieved June 2, 2021.

    Open source URL
  4. [4]
    mitre-attackS0617
    Open source URL
  5. [5]
    mitre-attackS0617
    Open source URL
  6. [6]
    mitre-attackS0617
    Open source URL
  7. [7]
    FireEye FiveHands April 2021

    McLellan, T. and Moore, J. et al. (2021, April 29). UNC2447 SOMBRAT and FIVEHANDS Ransomware: A Sophisticated Financial Threat. Retrieved June 2, 2021.

    Open source URL
  8. [8]
    FireEye FiveHands April 2021

    McLellan, T. and Moore, J. et al. (2021, April 29). UNC2447 SOMBRAT and FIVEHANDS Ransomware: A Sophisticated Financial Threat. Retrieved June 2, 2021.

    Open source URL
  9. [9]
    FireEye FiveHands April 2021

    McLellan, T. and Moore, J. et al. (2021, April 29). UNC2447 SOMBRAT and FIVEHANDS Ransomware: A Sophisticated Financial Threat. Retrieved June 2, 2021.

    Open source URL
  10. [10]
    FireEye FiveHands April 2021

    McLellan, T. and Moore, J. et al. (2021, April 29). UNC2447 SOMBRAT and FIVEHANDS Ransomware: A Sophisticated Financial Threat. Retrieved June 2, 2021.

    Open source URL
  11. [11]
    FireEye FiveHands April 2021

    McLellan, T. and Moore, J. et al. (2021, April 29). UNC2447 SOMBRAT and FIVEHANDS Ransomware: A Sophisticated Financial Threat. Retrieved June 2, 2021.

    Open source URL
  12. [12]
    FireEye FiveHands April 2021

    McLellan, T. and Moore, J. et al. (2021, April 29). UNC2447 SOMBRAT and FIVEHANDS Ransomware: A Sophisticated Financial Threat. Retrieved June 2, 2021.

    Open source URL
  13. [13]
    FireEye FiveHands April 2021

    McLellan, T. and Moore, J. et al. (2021, April 29). UNC2447 SOMBRAT and FIVEHANDS Ransomware: A Sophisticated Financial Threat. Retrieved June 2, 2021.

    Open source URL
  14. [14]
    FireEye FiveHands April 2021

    McLellan, T. and Moore, J. et al. (2021, April 29). UNC2447 SOMBRAT and FIVEHANDS Ransomware: A Sophisticated Financial Threat. Retrieved June 2, 2021.

    Open source URL
  15. [15]
    FireEye FiveHands April 2021

    McLellan, T. and Moore, J. et al. (2021, April 29). UNC2447 SOMBRAT and FIVEHANDS Ransomware: A Sophisticated Financial Threat. Retrieved June 2, 2021.

    Open source URL
  16. [16]
    FireEye FiveHands April 2021

    McLellan, T. and Moore, J. et al. (2021, April 29). UNC2447 SOMBRAT and FIVEHANDS Ransomware: A Sophisticated Financial Threat. Retrieved June 2, 2021.

    Open source URL
  17. [17]
    FireEye FiveHands April 2021

    McLellan, T. and Moore, J. et al. (2021, April 29). UNC2447 SOMBRAT and FIVEHANDS Ransomware: A Sophisticated Financial Threat. Retrieved June 2, 2021.

    Open source URL
  18. [18]
    FireEye FiveHands April 2021

    McLellan, T. and Moore, J. et al. (2021, April 29). UNC2447 SOMBRAT and FIVEHANDS Ransomware: A Sophisticated Financial Threat. Retrieved June 2, 2021.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.