HelloKitty ransomware gang also targets victims with DDoS attacks
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-20016 | Unauthenticated SQL Injection in SonicWall SMA100 SSL VPN CVE-2021-20016 is an unauthenticated SQL injection flaw (CWE-89) in the SonicWall SSL-VPN service on SMA 100 appliances. It is triggered remotely by malicious, unauthenticated requests to the appliance's web interface, allowing SQL injection against the backend database. Successful exploitation gives the attacker credential access — harvesting valid user credentials that can then be used to log into the SSL-VPN and pivot into the victim network. Any organization running an internet-facing SonicWall SSLVPN SMA100 appliance is affected, and CISA notes known ransomware use of this flaw. It was added to the CISA Known Exploited Vulnerabilities catalog on 2021-11-03 and carries a 40% EPSS probability of exploitation within 30 days (99th percentile), so it should be treated as actively exploited even though no public proof-of-concept is known. Do: Apply the SonicWall firmware update per vendor instructions, as required by the CISA KEV listing. Because ransomware operators are known to exploit this flaw, review SMA100 authentication and admin logs for unfamiliar logins, rotate exposed credentials, and restrict the appliance to trusted source IPs until it is patched. CVSS has not yet been scored, but the 40% EPSS (99th percentile) and KEV status warrant immediate patching of all internet-exposed units. | 9.8 | 40% | KEV ransomware |
| large≈ tens of thousands of internet-exposed SMA100 appliances (public scan counts of SonicWall SSL-VPN endpoints) | |
| CVE-2021-2002 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 8.0.22 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H). NVD description · AI analysis pending | 4.9 | 3% |
| — | ||
| CVE-2021-20021 +1 in the same advisory: …20022 | Improper Privilege Management in SonicWall Email Security 10.0.9.x Grants Admin Access CVE-2021-20021 is an improper privilege management flaw (CWE-269) in SonicWall Email Security version 10.0.9.x. An unauthenticated remote attacker can trigger it by sending a crafted HTTP request to the vulnerable host, which allows the attacker to create a new administrative account on the Email Security instance. That administrative access gives an attacker full control over the email security platform (CVSS 9.8 with high confidentiality, integrity, and availability impact), enabling persistence, manipulation of email filtering, and a foothold from which to target downstream mail infrastructure. Any organization running SonicWall Email Security 10.0.9.x is affected, whether on hardware appliances (3300, 4300, 5050, 7050, 8300, 9000, 5000, 7000), as a virtual appliance, or via the hosted service. The flaw is being actively exploited in the wild: it was added to CISA's KEV on 2021-11-03 with known ransomware use (headlines tie SonicWall email appliance attacks to the HelloKitty gang), and EPSS estimates an 83.4% probability of exploitation within 30 days (100th percentile). Do: Upgrade SonicWall Email Security from 10.0.9.x to the latest patched release per SonicWall's instructions, as required by CISA KEV. Audit the deployment for unrecognized administrative accounts created by attackers, review management-interface HTTP logs for suspicious requests, and restrict exposure of the management interface to trusted networks. Because this bug was one of three SonicWall zero-days actively exploited with known ransomware use (HelloKitty), also hunt for signs of compromise and follow-on ransomware activity. | 9.8 group max | 83% | KEV ransomware |
| large≈ tens of thousands of deployments (order of 10k–100k systems) |
Full article350 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
November 01, 2021

The US FBI has published a flash alert warning private organizations of the evolution of the HelloKitty ransomware (aka FiveHands).
The U.S. Federal Bureau of Investigation (FBI) has sent out a flash alert warning private industry of a new feature of the HelloKitty ransomware gang (aka FiveHands).
According to the alert, the ransomware gang is launching distributed denial-of-service (DDoS) attacks as part of its extortion activities.
“Hello Kitty/FiveHands actors aggressively apply pressure to victims typically using the double extortion technique. In some cases, if the victim does not respond quickly or does not pay the ransom, the threat actors will launch a Distributed Denial of Service (DDoS) attack on the victim company’s public facing website.” reads the flash alert.
The ransomware gang targets their victims’ websites with DDoS attacks if they refuse to pay the ransom. The HelloKitty ransomware group, like other ransomware gangs, implements a double extortion model, stealing sensitive documents from victims before encrypting them. Then the threat actors threaten to leak the stolen data to force the victim into paying the ransom.
The HelloKitty/FiveHands gang is known to demand varying ransom payments in Bitcoin (BTC) that are commensurate with the economic capabilities of the victims.
The group’s operators use several techniques to breach the targets’ networks, such as exploiting SonicWall flaws (e.g., CVE-2021-20016, CVE-2021-20021, CVE-2021-20022, CVE-2021-2002) or using compromised credentials.
“Once inside the network, the threat actor will use publicly available penetration tool suites such as Cobalt Strike, Mandiant’s Commando, or PowerShell Empire preloaded with publicly available tools like Bloodhound and Mimikatz to map the network and escalate privileges before exfiltration and encryption.” continues the alert.
The HelloKitty ransomware operators have been active since November 2020, since July, they are using a Linux variant of their malware to target VMware ESXi virtual machine platform.
The alert published by the FBI also includes a collection of indicators of compromise (IOCs) to help organizations to prevent HelloKitty infections.
Follow me on Twitter: @securityaffairs and Facebook
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, cybercrime)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/124059/malware/hellokitty-ransomware-fbi-alert.html