Skip to content

hellcat

Inactive

20 tracked victims · First seen Oct 25, 2024 · Last seen Apr 7, 2025

About

Aggregated threat-intel description

HellCat is a ransomware-as-a-service group that formed in Q4 2024 and quickly became notable for high-profile attacks against Schneider Electric, Telefónica, and Israel's Knesset, primarily gaining initial access via stolen Jira credentials harvested by infostealer malware, targeting critical infrastructure and government entities.

Sectors: Technology, Education, Government · Countries: US, CN, DE

Recent victims

View all →
VictimSectorCountryPostedStatus
Potomac Financial ServicesFinancial ServicesUSApr 10, 2025
P**o***Not FoundApr 7, 2025
CVTETechnologyCNApr 7, 2025
HighWire PressTechnologyUSApr 5, 2025
RacamiTechnologyUSApr 5, 2025
AssecoTechnologyPLApr 5, 2025
LeoVegas ABTelecommunicationSEApr 5, 2025
Transsion HoldingsTechnologyCNMar 29, 2025
Grupo SantillanaEducationESMar 25, 2025
OmnitracsTechnologyUSMar 25, 2025
Electronics For ImagingTechnologyUSMar 17, 2025
Ascom Holding AGTechnologyCHMar 16, 2025
OneDealerNot FoundDEFeb 28, 2025
Car Care Plan - TurkeyFinancialTRDec 26, 2024
Sistem Informasi Pengelolaan Keuangan Daerah (SIPKD)GovernmentIDDec 25, 2024
Pinger - USABusiness ServicesUSDec 25, 2024
College of Business - TanzaniaEducationTZNov 4, 2024
Ministry of Education - JordanEducationJONov 4, 2024
Schneider Electric - FranceEnergyFRNov 4, 2024
The Knesset - IsraelGovernmentILOct 25, 2024

All ransomware groups · Dark web intelligence