About
Aggregated threat-intel descriptionKawa4096 is a ransomware group that emerged in June 2025, targeting multinational corporations across finance, education, and services sectors primarily in the US and Japan, using partial-encryption (25% of each file chunk) with Salsa20 and a leak site styled after Akira's retro terminal aesthetic, claiming at least 11 victims.
Sectors: Financial Services, Healthcare, Public Sector · Countries: US, JP, DE
Recent victims
View all →| Victim | Sector | Country | Posted | Status |
|---|---|---|---|---|
| ********.org | Not Found | US | Jul 29, 2025 | |
| **********.net | Not Found | US | Jul 27, 2025 | |
| **********.com | Not Found | US | Jul 27, 2025 | |
| icmconv.com | Not Found | US | Jul 22, 2025 | |
| carestlhealth.org | Healthcare | US | Jul 22, 2025 | |
| sbamh.org | Healthcare | US | Jul 22, 2025 | |
| gatewaycsb.org | Public Sector | US | Jul 7, 2025 | |
| heimhaus.de | Not Found | DE | Jul 7, 2025 | |
| tokiomarine-nichido.co.jp | Financial Services | JP | Jul 1, 2025 | |
| www.ogr-jp.com | Not Found | JP | Jul 1, 2025 | |
| www.malonebailey.com | Financial Services | US | Jun 30, 2025 | |
| **********-*******.co.jp | Not Found | JP | Jun 30, 2025 | |
| *************.org | Not Found | Jun 30, 2025 | ||
| Morningsideservices | Not Found | US | Jun 27, 2025 | |
| ******.de | Not Found | DE | Jun 27, 2025 | |
| ******.com | Not Found | US | Jun 27, 2025 | |
| ******.org | Not Found | US | Jun 27, 2025 |