HellCat is a ransomware-as-a-service group targeting critical infrastructure using stolen Jira credentials.
Analyst brief
HellCat is a ransomware-as-a-service group that emerged in late 2024. They primarily target critical infrastructure and government entities. Their main TTP involves gaining initial access via stolen Jira credentials harvested by infostealer malware. Defenders should prioritize monitoring for corporate credential leaks and detecting infostealer infections early.
hellcat
crime
HellCat is a ransomware-as-a-service group that formed in Q4 2024 and quickly became notable for high-profile attacks against Schneider Electric, Telefónica, and Israel's Knesset, primarily gaining initial access via stolen Jira credentials harvested by infostealer malware, targeting critical infrastructure and government entities.