An operator of the HelloKitty ransomware announced that he had changed the name of the malicious enterprise to “ HelloGookie ,” while also publishing passwords for previously leaked CD Projekt source code , Cisco network information, as well as decryption keys for old attacks.

The hacker who announced the rebranding goes by the name “Gookee/kapuchin0” and claims to be the original creator of the now-defunct HelloKitty ransomware. According to a researcher, the name change coincides with the emergence of a new dark web portal for the HelloGookie ransomware.
To celebrate the launch of the new operation, the attacker released four private decryption keys, which can be used to decrypt files in past attacks, as well as internal information stolen from Cisco in 2022 and passwords for the source code leaked for Gwent, Witcher 3, and Red Engine in 2021, following a breach at CD Projekt.
See also: Ransomware 2024: Only 28% of victims paid ransom
As first spotted by VX-Underground, a group of developers has already gained access to Witcher 3 from the leaked source code.
A spokesperson for the group told BleepingComputer that the leaked CD Projekt data is 450 GB of uncompressed data and contains source code for Witcher 3, Gwent, Cyberpunk, various console SDKs (PS4/PS5 XBOX NINTENDO) and some build logs.
According to BleepingComputer, the leak makes it possible to launch a developer build of Witcher 3.
HelloKitty ransomware
HelloKitty was a ransomware operation that emerged in November 2020. It carried out numerous attacks on corporate networks, with the aim of stealing data and encrypting systems.
The first major attack came in February 2021, when CD Projekt Red, the developer of Cyberpunk 2077, Witcher 3, and Gwent, was breached. The gang encrypted the company's servers and stole source code. It later claimed to have sold the data, including code for the then-unreleased Witcher 3.
See also: Octapharma Plasma likely victim of ransomware attack
The ransomware operation gradually evolved, even releasing a variant Linux to target VMware ESXi machines.
In October 2023, hacker Gookee/kapuchin0 leaked the HelloKitty creator and source code to a hacking forum, signaling the end of the malicious work.
HelloKitty ransomware renamed to HelloGookie
Gookee/kapuchin0 now says the operation has changed its name to HelloGookie. While it has not reported any new victims, it has published stolen information from previous attacks on CD Projekt Red and Cisco (as mentioned above). The data leak site also includes four private decryption keys for an older version of the HelloKity ransomware encryptor, which could allow some victims to recover their files for free.
It remains to be seen whether HelloGookie will have the same success as HelloKitty ransomware.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Ransomware protection
Protecting against ransomware attacks requires preventative measures. One of these is informing and educating users to recognize and avoid suspicious emails or links that may contain malware.
It is also important to keep the operating system and all installed programs up to date, as updates often include security that can protect against new forms of ransomware (e.g. the new HelloGookie).
See also: Akira ransomware has compromised over 250 organizations
Backing up your data is essential to protect your most important data. Using reliable software antivirus is another important practice for protecting against ransomware attacks.
Finally, using tools to restrict user rights and implementing the principle of least privilege can help protect against ransomware attacks by limiting the malware's ability to extend its impact on the system.
Source: www.bleepingcomputer.com
