A threat actor has leaked the full source code of the HelloKitty ransomware to a Russian-language hacking forum .

This leak was discovered by cybersecurity 3xp0rt, who spotted a threat actor named “kapuchin0” leaking the “first branch” of the HelloKitty ransomware.
See also: McLaren Health Care – Blackcat ransomware: Patient data leak on the dark web?
Ενώ ο πηγαίος κώδικας κυκλοφόρησε από κάποιον με το όνομα ‘kapuchin0’, ο 3xp0rt είπε, ότι ο απειλητικός φορέας χρησιμοποιεί επίσης το ψευδώνυμο ‘Gookee’.
He ('Gookee') has been linked to malware. In 2020, he attempted to access Sony Network Japan and was linked to a Ransomware-as-a-Service operation called “Gookee Ransomware”. He also attempted to sell the malware's source code via a hacker forum.
3xp0rt believes that kapuchin0/Gookee is the developer of the HelloKitty ransomware, who now says, “We are preparing a new product that is much more interesting than Lockbit.”
The released hellokitty.zip file contains a Microsoft Visual Studio solution that allows for the encryption and decryption of HelloKitty, as well as the corresponding NTRUEncrypt library that this version of the ransomware uses to encrypt files.
Ransomware expert Michael Gillespie confirmed that this is the genuine source code for HelloKitty, which was used when the ransomware was launched in 2020
While the release of ransomware source code can be useful for the research side of security, the public availability of this code has its disadvantages.
When HiddenTear was released (for “educational purposes”) and the source code of the Babuk ransomware, malicious users quickly developed the code to start their own extortion operations.
See also: Hacking groups now deploy ransomware within 24 hours of breaching victims
To date, more than nine ransomware variants continue to use the original Babuk code as a base to create their own encryptors.
What is HelloKitty?
HelloKity is a ransomware operation that is run by a person and has been active since November 2020. A victim posted on the BleepingComputer forums, with the FBI later publishing in January 2021 a (PIN).
The gang is known for hacking corporate networks, stealing data, and encrypting systems. The encrypted files and stolen data are then used as a means of blackmail, where the perpetrators threaten to leak data if a ransom is not paid.
HelloKitty is known for many attacks and is used by other ransomware operations. However, the most infamous attack occurred in February 2021, at the company CD Projekt Red.
During this attack, the perpetrators claimed to have stolen Cyberpunk 2077, Witcher 3, Gwent, and the source code of other games, which they said were sold.
In the summer of 2021, the ransomware group began using a Linux that attacks the VMware ESXi virtual machine platform.
The HelloKitty ransomware and its variants have also been used under other names, such as DeathRansom, Fivehands, and possibly Abyss Locker.

See also: Number of victims reporting to ransomware gang “leak sites” increases
The FBI has published an extensive collection of indicators of compromise (IOCs) in its 2021 recommendations, intended to help cybersecurity experts and system administrators protect themselves from attacks coordinated by the HelloKitty ransomware gang.
However, as the encryptor has changed over time, the IOCs are likely to have become outdated.
Source: bleepingcomputer.com
