Hellcat ransomware gang
Threat Actor
Hellcat ransomware gang emerged in mid-2024 and employs a ransomware-as-a-service (RaaS) model, offering ransomware tools and infrastructure to affiliates in exchange for a share of the profits. The group has so far focused on high-value targets, such as government and critical sectors like energy and education.
Hellcat’s double extortion tactics indicate a deeper psychological element aimed at humiliation and public pressure.
Incidents Associated with this Threat
- March 16, 2025: Swiss Global Solutions Provider Ascom Confirms Cyberattack
- February 25, 2025: French Orange Group Confirms Cyberattack
- January 10, 2025: Data Breached at Telefónica, a Spanish Telecommunications Company
- November 3, 2024: Ransomware Attack at Schneider Electric
Malware Used by this Threat Actor
No malware identified for this threat actor.
