Skip to content

kawa4096

Inactive

17 tracked victims · First seen Jun 19, 2025 · Last seen Jul 28, 2025

About

Aggregated threat-intel description

Kawa4096 is a ransomware group that emerged in June 2025, targeting multinational corporations across finance, education, and services sectors primarily in the US and Japan, using partial-encryption (25% of each file chunk) with Salsa20 and a leak site styled after Akira's retro terminal aesthetic, claiming at least 11 victims.

Sectors: Financial Services, Healthcare, Public Sector · Countries: US, JP, DE

Recent victims

View all →
VictimSectorCountryPostedStatus
********.orgNot FoundUSJul 29, 2025
**********.netNot FoundUSJul 27, 2025
**********.comNot FoundUSJul 27, 2025
icmconv.comNot FoundUSJul 22, 2025
carestlhealth.orgHealthcareUSJul 22, 2025
sbamh.orgHealthcareUSJul 22, 2025
gatewaycsb.orgPublic SectorUSJul 7, 2025
heimhaus.deNot FoundDEJul 7, 2025
tokiomarine-nichido.co.jpFinancial ServicesJPJul 1, 2025
www.ogr-jp.comNot FoundJPJul 1, 2025
www.malonebailey.comFinancial ServicesUSJun 30, 2025
**********-*******.co.jpNot FoundJPJun 30, 2025
*************.orgNot FoundJun 30, 2025
MorningsideservicesNot FoundUSJun 27, 2025
******.deNot FoundDEJun 27, 2025
******.comNot FoundUSJun 27, 2025
******.orgNot FoundUSJun 27, 2025

All ransomware groups · Dark web intelligence