In August 2025, a new ransomware threat emerged with capabilities that fundamentally changed how organizations should approach enterprise security.
Kraken, a Russian-speaking cybercriminal group, began executing sophisticated attacks targeting large organizations across multiple continents.
What makes Kraken particularly dangerous is its ability to attack Windows, Linux, and VMware ESXi systems with platform-specific tools, making it one of the first truly cross-platform ransomware threats to gain widespread notoriety in enterprise circles.
The Kraken group appears to be connected to the HelloKitty ransomware operation, with security researchers suspecting the group emerged from the remnants of that previous criminal organization.
.webp)
This connection becomes evident through shared ransom note filenames and explicit references on the group’s leak site.
.webp)