HomeSecurityHelloKitty ransomware becomes "HelloGookie" - CD Projekt & Cisco data leak

HelloKitty ransomware becomes “HelloGookie” – CD Projekt & Cisco data leak

An operator of the HelloKitty ransomware announced that he had changed the name of the malicious enterprise to “ HelloGookie ,” while also publishing passwords for previously leaked CD Projekt source code , Cisco network information, as well as decryption keys for old attacks.

HelloKitty ransomware HelloGookie CD Projekt & Cisco

The hacker who announced the rebranding goes by the name “Gookee/kapuchin0” and claims to be the original creator of the now-defunct HelloKitty ransomware. According to a researcher, the name change coincides with the emergence of a new dark web portal for the HelloGookie ransomware.

To celebrate the launch of the new operation, the attacker released four private decryption keys, which can be used to decrypt files in past attacks, as well as internal information stolen from Cisco in 2022 and passwords for the source code leaked for Gwent, Witcher 3, and Red Engine in 2021, following a breach at CD Projekt.

See also: Ransomware 2024: Only 28% of victims paid ransom

As first spotted by VX-Underground, a group of developers has already gained access to Witcher 3 from the leaked source code.

A spokesperson for the group told BleepingComputer that the leaked CD Projekt data is 450 GB of uncompressed data and contains source code for Witcher 3, Gwent, Cyberpunk, various console SDKs (PS4/PS5 XBOX NINTENDO) and some build logs.

According to BleepingComputer, the leak makes it possible to launch a developer build of Witcher 3.

HelloKitty ransomware

HelloKitty was a ransomware operation that emerged in November 2020. It carried out numerous attacks on corporate networks, with the aim of stealing data and encrypting systems.

The first major attack came in February 2021, when CD Projekt Red, the developer of Cyberpunk 2077, Witcher 3, and Gwent, was breached. The gang encrypted the company's servers and stole source code. It later claimed to have sold the data, including code for the then-unreleased Witcher 3.

See also: Octapharma Plasma likely victim of ransomware attack

The ransomware operation gradually evolved, even releasing a variant Linux to target VMware ESXi machines.

In October 2023, hacker Gookee/kapuchin0 leaked the HelloKitty creator and source code to a hacking forum, signaling the end of the malicious work.

HelloKitty ransomware renamed to HelloGookie

Gookee/kapuchin0 now says the operation has changed its name to HelloGookie. While it has not reported any new victims, it has published stolen information from previous attacks on CD Projekt Red and Cisco (as mentioned above). The data leak site also includes four private decryption keys for an older version of the HelloKity ransomware encryptor, which could allow some victims to recover their files for free.

It remains to be seen whether HelloGookie will have the same success as HelloKitty ransomware.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

HelloKitty ransomware becomes "HelloGookie" - CD Projekt & Cisco data leak

Ransomware protection

Protecting against ransomware attacks requires preventative measures. One of these is informing and educating users to recognize and avoid suspicious emails or links that may contain malware.

It is also important to keep the operating system and all installed programs up to date, as updates often include security that can protect against new forms of ransomware (e.g. the new HelloGookie).

See also: Akira ransomware has compromised over 250 organizations

Backing up your data is essential to protect your most important data. Using reliable software antivirus is another important practice for protecting against ransomware attacks.

Finally, using tools to restrict user rights and implementing the principle of least privilege can help protect against ransomware attacks by limiting the malware's ability to extend its impact on the system.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS