Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Kawa4096 / Kawalocker

Kawa4096 is a ransomware group that emerged in June 2025, targeting multinational corporations across finance, education, and services sectors primarily in the US and Japan, using partial-encryption (25% of each file chunk) with Salsa20 and a leak site styled after Akira's retro terminal aesthetic, claiming at least 11 victims.

Victims
17
 
First Discovered
2025-06-27
victim
Last Discovered
2025-07-29
victim
Inactive Since
289
days
Avg Delay
8.3
days
Infostealer
11.1%
victims with domain
Countries
3
hit
View Victims on World Map View Group Statistics
Attack Velocity — Last 12 months

Known Locations (1)
Favicon Title Type Available Last Visit Server Info FQDN
favicon Kawa4096 No 2026-04-28T07:24:20 kawasa2qo7345dt7ogxmx7qmn6z2hnwaoi3h5aeosupozkddqwp6lqqd.onion

Target
Top 5 Activity Sectors
  • Healthcare 2
  • Financial Services 2
  • Public Sector 1
Top 5 Countries
  • US flag United States 11
  • JP flag Japan 3
  • DE flag Germany 2

Heatmap

YARA Rules (1)

Indicators of Compromise (IoCs) (3)
Email 1 Hash SHA256 1 tox 1
Type IOC
Email kawa4096@onionmail.org
Hash SHA256 f3a6d4ccdd0f663269c3909e74d6847608b8632fb2814b0436a4532b8281e617
tox 6A340207246B47E37F6D094D2236E5C6242B6E4461EEF8021FED2C9855240C3E11AEE886FAAF

Victims (17)
Logo
Discovered: 2025-07-29 (9mo ago)  ·  Attack est.: 2025-07-28
********.org…
Logo
Discovered: 2025-07-27 (9mo ago)
**********.net…
Logo
Discovered: 2025-07-27 (9mo ago)
**********.com…
Logo
Discovered: 2025-07-22 (9mo ago)  ·  Attack est.: 2025-06-19
icmconv.com…
Logo
Discovered: 2025-07-22 (9mo ago)  ·  Attack est.: 2025-06-28
carestlhealth.org…
Logo
Discovered: 2025-07-22 (9mo ago)  ·  Attack est.: 2025-07-20
sbamh.org…
Logo
Discovered: 2025-07-07 (10mo ago)  ·  Attack est.: 2025-06-25
gatewaycsb.org…
Logo
Discovered: 2025-07-07 (10mo ago)  ·  Attack est.: 2025-06-22
www.heimhaus.de…
Logo
Discovered: 2025-07-01 (10mo ago)  ·  Attack est.: 2025-06-26
tokiomarine-nichido.co.jp…
Logo
Discovered: 2025-07-01 (10mo ago)  ·  Attack est.: 2025-06-28
www.ogr-jp.com…
Logo
Discovered: 2025-06-30 (10mo ago)  ·  Attack est.: 2025-06-24
www.malonebailey.com…
Logo
Discovered: 2025-06-30 (10mo ago)  ·  Attack est.: 2025-06-26
**********-*******.co.jp…
Logo
Discovered: 2025-06-30 (10mo ago)  ·  Attack est.: 2025-06-28
*************.org…
Logo
Discovered: 2025-06-27 (10mo ago)  ·  Attack est.: 2025-06-20
www.morningsideservices.com…
Logo
Discovered: 2025-06-27 (10mo ago)  ·  Attack est.: 2025-06-22
www.******.de…
Logo
Discovered: 2025-06-27 (10mo ago)  ·  Attack est.: 2025-06-24
www.******.com…
Logo
Discovered: 2025-06-27 (10mo ago)  ·  Attack est.: 2025-06-25
******.org…