HellCat
Hellcat Ransomware is a ransomware threat/group referenced across multiple Splunk analytic stories and detections. The provided content links Hellcat to ransomware-related behaviors including stopping backup and security services, high-frequency process termination, creation of ransomware note files, abuse of netsh to modify firewall settings, suspicious PowerShell activity, SQL Server abuse, ESXi SSH brute force, suspicious named-pipe activity, rundll32 and regsvcs abuse, BITSAdmin download activity, LSASS dumping via comsvcs.dll, and high-frequency copying of files on network shares. The content also states that in March 2025 the HELLCAT ransomware group leaked 700 internal documents allegedly from Jaguar Land Rover (JLR) after compromising Jira credentials; the leaked material reportedly included development logs, source code, and a large employee dataset containing usernames, email addresses, display names, and time zones. The content further cites reporting by Cyfirma and Hudson Rock linking a hacker using the moniker "Rey" to the HellCat ransomware group. High-confidence targeting details beyond the JLR incident are not provided in the content.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In March, the HELLCAT ransomware group leaked 700 internal documents, purportedly part of a compromise of JLR's internal network using Jira credentials and also included development logs, source code, and a large employee dataset with usernames, email addresses, display names, and time zones, according to an analysis by threat intelligence firm Cyfirma.
IOCs tracked for this family
31 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
Recent activity
31 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family referenced in the associated analytic stories.
Ransomware family referenced in an associated analytic story.
Associated Analytic Story ... Hellcat Ransomware
Ransomware family mentioned as relevant to a detection for unusually frequent process termination, a behavior linked to ransomware execution.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.