Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 12:44:22 UTC Tool: HELLOKITTY Names HELLOKITTY HelloKitty KittyCrypt Category Malware Type Ransomware, Big Game Hunting Description (FireEye) HELLOKITTY ransomware—used to target Polish video game developer CD Projekt Red—is reportedly built from DEATHRANSOM. HELLOKITTY is named after a mutex named ‘HELLOKITTYMutex,’ used when the malware executable is launched Information MITRE ATT&CK Malpedia Playbook Last change to this tool card: 18 June 2024 Download this tool card in JSON format All groups using tool HELLOKITTY Changed Name Country Observed https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=fed08e25-fd63-4def-93d4-0fa8555fc680 Page 1 of 2 APT groups   UNC2447 [Unknown] 2020   1 group listed (1 APT, 0 other, 0 unknown) ↑ Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=fed08e25-fd63-4def-93d4-0fa8555fc680 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=fed08e25-fd63-4def-93d4-0fa8555fc680 Page 2 of 2