HackerFeeds
All ransomware groups

hellcat

20 tracked victims
·first seen 2024-10-25·last activity 2025-04-07

Group profile

HellCat is a ransomware-as-a-service group that formed in Q4 2024 and quickly became notable for high-profile attacks against Schneider Electric, Telefónica, and Israel's Knesset, primarily gaining initial access via stolen Jira credentials harvested by infostealer malware, targeting critical infrastructure and government entities.

Recent victims

DateWebsite / victimSectorCountry
2025-04-07
potomacfinancialadvisors.com
Potomac Financial Servicespotomacfinancialadvisors.com
Financial ServicesUS
2025-04-07Financial Services
2025-04-07TechnologyCN
2025-03-18
highwirepress.com
HighWire Presshighwirepress.com
TechnologyUS
2025-04-05TechnologyUS
2025-04-05TechnologyPL
2025-04-05TelecommunicationSE
2025-03-29
transsion.com
Transsion Holdingstranssion.com
TechnologyCN
2025-03-24
santillana.com
Grupo Santillanasantillana.com
EducationES
2025-03-24TechnologyUS
2025-03-17
efi.com
Electronics For Imagingefi.com
TechnologyUS
2025-03-15
ascom.com
Ascom Holding AGascom.com
TechnologyCH
2025-02-25Consumer ServicesDE
2024-12-26
carcareplan.com.tr
Car Care Plan - Turkeycarcareplan.com.tr
Consumer ServicesTR
2024-12-25
kemendagri.go.id
Sistem Informasi Pengelolaan Keuangan Daerah (SIPKD)kemendagri.go.id
Public SectorID
2024-12-25
pinger.com
Pinger - USApinger.com
Business ServicesUS
2024-11-04
cbe.ac.tz
College of Business - Tanzaniacbe.ac.tz
EducationTZ
2024-11-04
moe.gov.jo
Ministry of Education - Jordanmoe.gov.jo
EducationJO
2024-11-04
se.com
Schneider Electric - Francese.com
EnergyFR
2024-10-25
knesset.gov.il
The Knesset - Israelknesset.gov.il
Public SectorIL