The source code of the 2020 variant of HelloKitty ransomware was leaked on cybercrime forum
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-20016 | Unauthenticated SQL Injection in SonicWall SMA100 SSL VPN CVE-2021-20016 is an unauthenticated SQL injection flaw (CWE-89) in the SonicWall SSL-VPN service on SMA 100 appliances. It is triggered remotely by malicious, unauthenticated requests to the appliance's web interface, allowing SQL injection against the backend database. Successful exploitation gives the attacker credential access — harvesting valid user credentials that can then be used to log into the SSL-VPN and pivot into the victim network. Any organization running an internet-facing SonicWall SSLVPN SMA100 appliance is affected, and CISA notes known ransomware use of this flaw. It was added to the CISA Known Exploited Vulnerabilities catalog on 2021-11-03 and carries a 40% EPSS probability of exploitation within 30 days (99th percentile), so it should be treated as actively exploited even though no public proof-of-concept is known. Do: Apply the SonicWall firmware update per vendor instructions, as required by the CISA KEV listing. Because ransomware operators are known to exploit this flaw, review SMA100 authentication and admin logs for unfamiliar logins, rotate exposed credentials, and restrict the appliance to trusted source IPs until it is patched. CVSS has not yet been scored, but the 40% EPSS (99th percentile) and KEV status warrant immediate patching of all internet-exposed units. | 9.8 | 40% | KEV ransomware |
| large≈ tens of thousands of internet-exposed SMA100 appliances (public scan counts of SonicWall SSL-VPN endpoints) | |
| CVE-2021-2002 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 8.0.22 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H). NVD description · AI analysis pending | 4.9 | 3% |
| — | ||
| CVE-2021-20021 +1 in the same advisory: …20022 | Improper Privilege Management in SonicWall Email Security 10.0.9.x Grants Admin Access CVE-2021-20021 is an improper privilege management flaw (CWE-269) in SonicWall Email Security version 10.0.9.x. An unauthenticated remote attacker can trigger it by sending a crafted HTTP request to the vulnerable host, which allows the attacker to create a new administrative account on the Email Security instance. That administrative access gives an attacker full control over the email security platform (CVSS 9.8 with high confidentiality, integrity, and availability impact), enabling persistence, manipulation of email filtering, and a foothold from which to target downstream mail infrastructure. Any organization running SonicWall Email Security 10.0.9.x is affected, whether on hardware appliances (3300, 4300, 5050, 7050, 8300, 9000, 5000, 7000), as a virtual appliance, or via the hosted service. The flaw is being actively exploited in the wild: it was added to CISA's KEV on 2021-11-03 with known ransomware use (headlines tie SonicWall email appliance attacks to the HelloKitty gang), and EPSS estimates an 83.4% probability of exploitation within 30 days (100th percentile). Do: Upgrade SonicWall Email Security from 10.0.9.x to the latest patched release per SonicWall's instructions, as required by CISA KEV. Audit the deployment for unrecognized administrative accounts created by attackers, review management-interface HTTP logs for suspicious requests, and restrict exposure of the management interface to trusted networks. Because this bug was one of three SonicWall zero-days actively exploited with known ransomware use (HelloKitty), also hunt for signs of compromise and follow-on ransomware activity. | 9.8 group max | 83% | KEV ransomware |
| large≈ tens of thousands of deployments (order of 10k–100k systems) |
Full article394 words · extracted from securityaffairs.com · click to collapse

A threat actor has leaked the source code for the first version of the HelloKitty ransomware on a Russian-speaking cybercrime forum.
Cybersecurity researchers 3xp0rt reported that a threat actor that goes online with the moniker ‘kapuchin0’ (and also uses the alias Gookee) has leaked the source code of the HelloKitty ransomware on the XSS forum.
kapuchin0 claims that the leaked code is the first breach of the HelloKitty ransomware.

BleepingComputer reported that the threat actor is also claiming to be developing a more powerful encryptor.
“We are preparing a new product and much more interesting than Lockbit.” said kapuchin0.
The leaked archive includes a Microsoft Visual Studio project that can be used to create the HelloKitty ransomware and the related decryptor.
It should be noted however that the leaker, kapuchin0, states he (Hello Kitty ransomware?) no longer need this and they intend on developing something superior to Lockbit ransomware group. pic.twitter.com/YJavUu53v3
— vx-underground (@vxunderground) October 7, 2023
BleepingComputer was able to verify with the help of the popular malware researcher Michael Gillespie that that source code is legitimate and is related to the first version of the ransomware that was employed in 2020.
The availability of the source in the cybercrime ecosystem can allow threat actors to develop their own version of the Hello Kitty ransomware.
The HelloKitty gang has been active since January 2021. In November 2021, the US FBI has published a flash alert warning private organizations of the evolution of the HelloKitty ransomware (aka FiveHands). According to the alert, the ransomware gang is launching distributed denial-of-service (DDoS) attacks as part of its extortion activities.
The ransomware gang targets their victims’ websites with DDoS attacks if they refuse to pay the ransom. The HelloKitty ransomware group, like other ransomware gangs, implements a double extortion model, stealing sensitive documents from victims before encrypting them. Then the threat actors threaten to leak the stolen data to force the victim into paying the ransom.
The HelloKitty/FiveHands gang is known to demand varying ransom payments in Bitcoin (BTC) that are commensurate with the economic capabilities of the victims.
The group’s operators use several techniques to breach the targets’ networks, such as exploiting SonicWall flaws (e.g., CVE-2021-20016, CVE-2021-20021, CVE-2021-20022, CVE-2021-2002) or using compromised credentials.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, HelloKitty ransomware)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/152182/malware/hellokitty-ransomware-source-code-leaked.html