Skip to main content
Skip to main content
Microsoft Security Intelligence
6 entries found.
Updated on Jul 17, 2021

The HelloKitty ransomware group has been observed to use a Linux variant to target VMware’s ESXi virtual machine platform. They use the tactic known as double extortion, wherein they exfiltrate user information before encrypting their data.

This ransomware encrypts the data on your disk and can stop you from using your device or accessing your data. It encrypts files, renders them inaccessible, and demands payment for the decryption key.

For information about ransomware and other human-operated ransomware campaigns, read the following blog post: 

Alert level: severe
Updated on May 20, 2025
Alert level: severe
Updated on Apr 05, 2024
Alert level: severe
Updated on Aug 28, 2021
Alert level: severe
Updated on Apr 23, 2024
Alert level: severe
Updated on Apr 23, 2024
Alert level: severe