kawa4096 logo

kawa4096

1 incidentes 1 paises 1 sectores ransomware Ultimo: 2026-06-25
Aliases: KawaLocker
Ver en IntelTracker → APTTrail →
Kawa4096 is a ransomware group that emerged in June 2025, quickly gaining attention for its rapid and widespread activity, targeting multinational organizations primarily for financial gain. The group employs a double extortion model, exfiltrating data before encryption and threatening to publish stolen information on its Tor-based leak site. A distinctive characteristic of Kawa4096 is its mimicry of branding elements from other established ransomware groups, notably the Akira ransomware group's retro-style Tor leak site and the Qilin ransomware's ransom note format, a tactic likely employed to amplify psychological pressure and establish perceived credibility among victims. Kawa4096 operates under the aliases KaWaLocker and KaWa.

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1)

Paises objetivo (SOCRadar)

GermanyJapanUnited States

Sectores atacados

Finance (1)

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesSoftware PublishersHospitalsManufacturingConstructionPublic AdministrationBeverag & Tobacco ManufacturingEducational Services

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com