In August 2025, a new cyber threat emerged on the global security landscape, radically changing the balance. The Kraken ransomware, a Russian-speaking cybercriminal ring, began launching large-scale attacks against organizations, proving that traditional defense strategies are no longer enough.

Kraken's threat is not limited to the breadth of its targets, but rather its technological sophistication. It is one of the first ransomware to attempt comprehensive attacks on Windows, Linux, and VMware ESXi, leveraging specialized tools for each platform — a capability that has until now been primarily possessed by state-backed actors.
HelloKitty Ransomware Connection: An Old Team Returns
Investigations by several cybersecurity organizations indicate that Kraken did not start from scratch. There are indications that the group is a continuation or offshoot of the well-known HelloKitty ransomware operation , which had occupied international media attention in previous years.
See also: Ransomware: New groups emerge and LockBit returns
Similarities in payloads, file names, and even the structure of ransom notes reveal common roots.
A New Underground Forum for Cybercriminals
In September 2025, Kraken launched The Last Haven Board, a darknet hub designed to host communications, collaborations, and purchases between criminal groups.
The creation of such a platform shows that Kraken is not just aiming for profits through ransoms — it seeks to create an ecosystem. An environment within which it can expand its activity, recruit new partners, and trade data derived from breaches.
HelloKitty's support for Kraken on the new underground forum "The Last Haven Board" further strengthens the collaboration scenario.
See also: Chinese hackers abuse Anthropic's AI model Claude

Double Extortion Strategy and Multi-Stage Attacks
Cisco Talos analysts documented that Kraken is implementing a dual extortion tactic :
- Data theft and encryption ,
- Threat of publishing stolen files if payment is refused.
This model is becoming more common, as it increases pressure on victims and improves the chances of ransom payments.
The attack follows a strictly structured chain:
- initial entry via SMB vulnerability on exposed servers,
- theft of privileged credentials,
- presence stabilization with RDP,
- use Cloudflared for reverse tunnels,
- data export via SSH Filesystem.
The level of organization demonstrates operational maturity and clear knowledge of the defense mechanisms of the companies.
Technical Arsenal: From Benchmarking to Adaptive Encryption
Before the ransomware activates encryption, it performs a highly unusual process: a speed test (benchmark) to calculate how fast it can operate without exhausting system resources, which would trigger immediate detection.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: New phishing campaign targets hotel customers
It then proceeds to attack using a combination of RSA-4096 and ChaCha20, two of the strongest encryption algorithms.
Command line options allow operators to configure:
- the range of files to be encrypted,
- the depth of the process,
- delays that prevent detection.
For Windows, the typical command is in the form:
Encryptor.exe –key
The Linux and ESXi versions use ELF binaries with the ability to run in background mode (daemon) and support remote SSH connections for further automation.
Kraken intentionally avoids critical directories (e.g. Program Files) to keep the system operational — a tactic that allows negotiations to take place without completely collapsing the victim's environment.
See also: DoorDash: New data breach revealed

Why Kraken Worries Experts More Than Other Threats
Kraken is not just another ransomware. It is an ecosystem, an operational cybercrime platform , and an ever- evolving threat.
The combination of cross-platform capabilities, dark web collaboration infrastructure, and increased technical sophistication bodes well for the group's influence to grow in the coming months.
Experts warn that organizations must immediately reconsider their approach to cybersecurity, investing in:
- multi-layered defense,
- internal lateral movement monitoring,
- zero trust architecture,
- systematic patches to Internet-exposed services.
In a world where criminal groups now operate like businesses, the defenses of real businesses must evolve accordingly.
