Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

India’s NHRC Raises Alarm Over Digital Arrest Scams

June 16, 2026

Coinbase intoduces AI advisor, stock options, and pre-IPO markets in finance push

June 16, 2026

WIF Price Prediction: Smart Money Is Buying the Bounce — But the Bear Structure Hasn’t Broken

June 16, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»Kraken Uses Benchmarking to Enhance Ransomware Attacks
Kraken Uses Benchmarking to Enhance Ransomware Attacks
Security

Kraken Uses Benchmarking to Enhance Ransomware Attacks

February 5, 2026No Comments3 Mins Read

A series of big-game hunting incidents and double extortion attacks carried out by Kraken, a Russian-speaking operation that has emerged from the ashes of the HelloKitty cartel, was observed in August 2025 by Cisco Talos and detailed in an advisory published last week.

The group has been linked to intrusions where Server Message Block (SMB) flaws were abused for entry, followed by the use of Cloudflare for persistence and SSH Filesystem (SSHFS) for data theft before encryption.

Kraken’s toolkit spans Windows, Linux and VMware ESXi, giving it reach across many enterprise environments.

A New Ransomware Strain 

What’s new is Kraken’s unusual benchmarking step, which measures how quickly a victim machine can process encryption before the malware initiates its file-locking routine. This allows the attackers to tailor the encryption method for maximum impact while reducing the chance of triggering system instability or detection.

The group also announced a new underground discussion space, The Last Haven Board, on its leak site, in an effort to create a secure hub for cybercrime collaboration.

Kraken, active since February 2025, relies on double extortion and appears opportunistic rather than focused on specific sectors.

Victims listed on its site include organizations in the US, the UK, Canada, Denmark, Panama and Kuwait.

It applies the .zpsc extension, issues a ransom note titled readme_you_ws_hacked.txt and threatens to publish stolen files if contacted through its onion service.

Read more on ransomware leak sites: Leak Site Ransomware Victims Spike 13% in a Year 

External reporting and Talos observations indicate possible overlap with the HelloKitty threat group. Kraken’s leak portal references HelloKitty by name, and both groups use the same ransom note filename.

See also  Kraken is looking for a fight (and it has Robinhood in its sights)

The launch of Last Haven included claimed support from HelloKitty operators and WeaCorp, an exploit-buying outfit, adding weight to the theory that Kraken spun out from the earlier cartel.

Kraken Attack Tactics

Talos documented one case in which Kraken actors broke in through an exposed SMB service, extracted privileged credentials, then returned via Remote Desktop.

Afterward, they installed Cloudflare to maintain access, deployed SSHFS to browse and siphon data, and pushed the encryptor across the network via Remote Desktop Protocol (RDP). They demanded roughly $1m in Bitcoin and pledged decryption and non-disclosure after payment.

Key elements of Kraken’s tactics include:

  • Cross-platform encryptors

  • Benchmark-based encryption decisions

  • Multi-threaded modules targeting SQL databases, network shares, local drives and virtual machines

Talos attributed this activity to an increasingly organized group attempting to claim the space left vacant by the collapse of the HelloKitty cartel.

To defend against threats such as this, organizations should strengthen credential hygiene, limit exposure of remote services, harden backup strategies and adopt continuous monitoring to spot abnormal tunneling or data access activity early.

Source link

attacks Benchmarking Enhance Kraken ransomware

Related Posts

India’s NHRC Raises Alarm Over Digital Arrest Scams

June 16, 2026

Rokarolla Trojan Combines Banking Fraud With Device Surveillance

June 16, 2026

Pyra to Cease Operations Following Drift Hack, Launches Fund Withdrawal Portal

June 16, 2026

Oklahoma Raises Alarm Over Fake Crypto Returns

June 16, 2026
Top Posts

Spot Bitcoin ETF Excitement Hits Main Street, Google Search Indicates

October 20, 2023

New Bitcoin quantum proposal offers Satoshi Nakamoto a way to prove control without moving BTC

May 2, 2026

Aave crosses $1T in lending as it seeks more bank, fintech integrations

February 26, 2026

Type above and press Enter to search. Press Esc to cancel.