Threadlinqs IntelligenceStart free

Threat actorMixed: criminal (HelloKitty/Kinsing/TellYouThePass) and state-aligned DPRK (Andariel)Tracked since 2026-04

HelloKitty

Also known as:FiveHandsMoney LibraOnyx SleetPLUTONIUMSilent Chollima

As of 2026-05-30, HelloKitty is a Mixed: criminal (HelloKitty/Kinsing/TellYouThePass) and state-aligned DPRK (Andariel)-nexus threat actor tracked by Threadlinqs Intelligence across 1 threat spanning vulnerability. Also known as FiveHands, Money Libra, Onyx Sleet, PLUTONIUM.

Tracked threats
11 critical
First seen
2026-04-21
Last seen
2026-04-21
ATT&CK techniques
—No mapped techniques yet
Related CVEs
1Referenced by its activity
Attribution
Mixed: criminal (HelloKitty/Kinsing/TellYouThePass) and state-aligned DPRK (Andariel)Nation or origin
Nation: Mixed: criminal (HelloKitty/Kinsing/TellYouThePass) and state-aligned DPRK (Andariel) · 1 tracked threat(s) · Categories: VULNERABILITY