hellogookie
1 incidentes
0 paises
0 sectores
ransomware UA Ultimo: 2026-06-25
Aliases: FiveHands, HelloKitty, Gookee, Kapuchin0
Hellogookie is a ransomware group that emerged in April 2024 as a rebrand of the notorious HelloKitty ransomware operation. Its creator, known by the aliases Gookee, Kapuchin0, and Guki, shut down the original HelloKitty operation in October 2023, subsequently launching HelloGookie to continue ransomware activities with updated tactics. The group's primary motivation is financial extortion, employing double and triple extortion tactics. A defining characteristic of HelloGookie is its explicit attempt to avoid direct competition and potentially collaborate with other major ransomware groups, such as LockBit, while also openly recruiting individuals for voice phishing operations. HelloGookie operates under the direct control of its developer, who has a history of collaborating with other ransomware groups like Yanluowang, and is assessed with moderate confidence to be of Ukrainian origin.
RansomLook pivots
Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.
Abrir perfil →
Paises objetivo (SOCRadar)
United Arab Emirates
Australia
Belgium
Brazil
Germany
Spain
France
United Kingdom
Italy
Japan
Sectores objetivo (SOCRadar)
Other Information ServicesSoftware PublishersHospitalsAir TransportationManufacturingPublic AdministrationEducational ServicesEnergy & Utilities InsuranceEducational Support Services
URLs nuevas detectadas en IntelTracker