December 9, 2021 By David Bisson 2 min read

The HelloKitty ransomware group, best known for breaching and stealing data from video game developer CD Projekt Red, has added distributed denial-of-service (DDoS) attacks to its arsenal of extortion tactics.

Extortion Techniques Press Victims for Time

The FBI first detected HelloKitty in January 2021. The gang has made a name for itself by breaching and encrypting the video game developer. In addition, it stole the source code for several of the company’s games.

According to the FBI, the HelloKitty ransomware group tailors each ransom demand to its victims based upon their ability to pay. In the event victims don’t respond quickly enough or don’t pay the ransom, HelloKitty posts their data. They use the Babuk gang website to do this, or sell the data to a third-party broker.

They started using DDoS in November, reported Bleeping Computer. To be specific, the HelloKitty group used a Linux variant to target VMware’s ESXi virtual machine platform.

How Ransomware Extortion Has Changed

This tactic, known as double extortion, first emerged in 2019. With it, ransomware groups exfiltrate victims’ information in plaintext before encrypting their data. That way, the attackers can demand two ransoms. One will be in exchange for a decrypter. The other will be to confirm the attackers have deleted the stolen data from their servers.

Some also use triple extortion directing more ransom demands at a victim’s clients and suppliers. It may also involve extorting employees and customers, or targeting business partners with spear-phishing attacks.

Researchers may also refer to quadruple extortion. In this case, ransomware groups like HelloKitty use DDoS attacks as a means of putting pressure on their victims. Or, in quintuple extortion,  some newer ransomware variants like Yanluowang tell their victims to not contact law enforcement agencies or ransomware negotiators. They threaten to target non-compliant victims with DDoS attacks. They can also go after their business partners, as well as repeat the attack in a few weeks’ time and delete their data outright.

Defending Against DDoS-Powered Ransomware Gangs

HelloKitty’s use of DDoS attacks for extortion underscores the need for businesses and agencies to defend themselves against ransomware.

One of the ways they can do that is by using a solution to monitor data usage and access patterns. Such a tool can help spot ransomware gangs disguising themselves as privileged users and/or attempting to execute large data pulls.

Second, businesses can turn to an eXtended Detection and Response (XDR) platform as a means of streamlining threat detection and response across their entire infrastructure. Such a tool can help your people detect and respond more quickly. Thereby, it will help mitigate the impact of digital threats such as ransomware attacks.

Finally, use threat intelligence to defend against emerging ransomware attacks. Then, add that threat intelligence into security awareness training programs to educate employees about new ransomware threats.

More from News

Securing critical infrastructure with the carrot and stick

4 min read - It wasn’t long ago that cybersecurity was a fringe topic of interest. Now, headline-making breaches impact large numbers of everyday citizens. Entire cities find themselves under cyberattack. In a short time, cyber has taken an important place in the national discourse. Today, governments, regulatory agencies and companies must work together to confront this growing threat. So how is the federal government bolstering security for critical infrastructure? It looks like they are using a carrot-and-stick approach. Back in March 2022, the…

650,000 cyber jobs are now vacant: How to tackle the risk

4 min read - How far is the United States behind in filing cybersecurity jobs? As per Rep. Andrew Garbarino, R-N.Y., Chairman of the HHS Cybersecurity and Infrastructure Protection Subcommittee, overseas adversaries have a workforce advantage over FBI cyber personnel of 50 to one. His statements were made during a recent subcommittee hearing titled “Growing the National Cybersecurity Talent Pipeline.” Meanwhile, recent CyberSeek data shows over 650,000 cyber jobs to fill nationwide. Given the rising rate of cyberattacks, these numbers are truly alarming. How…

Will data backups save you from ransomware? Think again

4 min read - Backups are an essential part of any solid anti-ransomware strategy. In fact, research shows that the median recovery cost for ransomware victims that used backups is half the cost incurred by those that paid the ransom. But not all data backup approaches are created equal. A separate report found that in 93% of ransomware incidents, threat actors actively target backup repositories. This results in 75% of victims losing at least some of their backups during the attack, and more than…

Should you worry about state-sponsored attacks? Maybe not.

4 min read - More than ever, state-sponsored cyber threats worry security professionals. In fact, nation-state activity alerts increased against critical infrastructure from 20% to 40% from 2021 to 2022, according to a recent Microsoft Digital Defense Report. With the advent of the hybrid war in Ukraine, nation-state actors are launching increasingly sophisticated attacks. But is this the most prominent danger facing companies today? While nation-state-based attacks cannot be ignored, it looks like insider cyber incidents are far more common. In fact, for the…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today