KAWA4096 Ransomware Employs WMI Techniques to Delete Backup Snapshots

KAWA4096 Ransomware Employs WMI Techniques to Delete Backup Snapshots Trustwave SpiderLabs has played a crucial role in monitoring new ransomware variants in the incredibly unstable ransomware threat landscape of 2025, where dozens of new groups have emerged and caused extensive disruptions across multiple sectors. Among these, the KAWA4096 ransomware has beenidentifiedas a notable newcomer, first detected in June 2025. This strain has already claimed at least 11 victims, predominantly targeting...

Save to Folder

Choose a folder to save this article: