Kawa4096 Ransomware
TrackedThreat actor group tracked in the global ransomware database Β· Last disclosure: Jul 29, 2025
ThreatAI Analysis
Compiled from the ransomware.live profile for Kawa4096 and from this database. Figures and technique mappings are quoted from the source data, not inferred.
Kawa4096 is a ransomware group which has targeted 17 victims across 3 countries so far, primarily using partial encryption methods against firms in the financial, healthcare, and public sectors.
Who Kawa4096 is
Kawa4096 is a ransomware group that emerged in June 2025, targeting multinational corporations across finance, education, and services sectors primarily in the US and Japan, using partial-encryption (25% of each file chunk) with Salsa20 and a leak site styled after Akira's retro terminal aesthetic, claiming at least 11 victims.
Recorded activity
Disclosures attributed to Kawa4096 in this database run from June 2025 to July 2025, totalling 17 victims β 0.1% of everything tracked here. Kawa4096 has listed victims in 3 countries in this database, most often United States, followed by Japan and Germany. The sectors appearing most in its listings are Healthcare, Financial Services, Public Sector.
Indicators of compromise
- f3a6d4ccdd0f663269c3909e74d6847608b8632fb2814b0436a4532b8281e617
- [email protected]
Showing a sample of 1 SHA256, 1 EMAIL on file. Hashes and network indicators published for Kawa4096. Leak-site addresses are deliberately excluded. Indicators age quickly β treat a match as a starting point for investigation, and an absence of matches as no assurance.
YARA detection rules
kawa4096.yar
/*
kawa4096 ransomware
*/
rule kawa4096_Ransomnote
{
meta:
author = "ransomware.live"
family = "ransomware.kawa4096"
description = "Detects kawa4096 ransomware ransom note or artifact"
date = "2026-05-04"
severity = 7
score = 70
strings:
$name1 = "kawa4096" ascii nocase
$name2 = "KAWA4096" ascii
$onion = "kawa4096.onion" ascii nocase
condition:
any of them
}
Community-contributed rules for Kawa4096, reproduced as published. Test them against your own corpus before relying on them: rule quality and false-positive behaviour vary by author.
Threat Actor Analysis
Kawa4096 is a ransomware threat group that has disclosed 17 victims in publicly accessible leak site data, representing 0.1% of all ransomware attacks tracked in this database. The earliest victim disclosure attributed to Kawa4096 in our dataset dates to June 2025.
Geographically, Kawa4096 has targeted organisations in 3 countries. The most frequently targeted nation is United States with 11 victim organisations. Other heavily targeted nations include Japan, Germany.
Industry-wise, Kawa4096 shows a concentration in the Healthcare, Financial Services, Public Sector sectors. These industries are frequently targeted because they manage sensitive data, critical operations, or have lower tolerance for operational downtime β conditions that increase ransom payment likelihood.
Like most modern ransomware operations, Kawa4096 likely employs a double extortion model: encrypting victim files while simultaneously exfiltrating data, creating dual pressure to pay the ransom. Victim organisations that refuse payment face having their data published on the group's dark web leak site.
Note: This profile is generated from public leak site disclosures aggregated via the ransomware.live API. Data is updated automatically. The table below lists the 17 most recent of the 17 disclosures we hold for this group; use the link beneath it to page through all of them.
Recent Victim Disclosures (showing 17 of 17)
| # | Organization | Country | Sector | Date |
|---|---|---|---|---|
| 1 | ********.org | πΊπΈ United States | β | Jul 29, 2025 |
| 2 | **********.com | πΊπΈ United States | β | Jul 27, 2025 |
| 3 | **********.net | πΊπΈ United States | β | Jul 27, 2025 |
| 4 | carestlhealth.org carestlhealth.org | πΊπΈ United States | Healthcare | Jul 22, 2025 |
| 5 | icmconv.com icmconv.com | πΊπΈ United States | β | Jul 22, 2025 |
| 6 | sbamh.org sbamh.org | πΊπΈ United States | Healthcare | Jul 22, 2025 |
| 7 | gatewaycsb.org gatewaycsb.org | πΊπΈ United States | Public Sector | Jul 7, 2025 |
| 8 | heimhaus.de heimhaus.de | π©πͺ Germany | β | Jul 7, 2025 |
| 9 | tokiomarine-nichido.co.jp tokiomarine-nichido.co.jp | π―π΅ Japan | Financial Services | Jul 1, 2025 |
| 10 | www.ogr-jp.com www.ogr-jp.com | π―π΅ Japan | β | Jul 1, 2025 |
| 11 | **********-*******.co.jp | π―π΅ Japan | β | Jun 30, 2025 |
| 12 | *************.org | β | β | Jun 30, 2025 |
| 13 | www.malonebailey.com malonebailey.com | πΊπΈ United States | Financial Services | Jun 30, 2025 |
| 14 | ******.com | πΊπΈ United States | β | Jun 27, 2025 |
| 15 | ******.de | π©πͺ Germany | β | Jun 27, 2025 |
| 16 | Morningsideservices Morningsideservices.com | πΊπΈ United States | β | Jun 27, 2025 |
| 17 | ******.org | πΊπΈ United States | β | Jun 27, 2025 |
Frequently Asked Questions
What is Kawa4096 ransomware?
Kawa4096 is a ransomware threat group that has claimed 17 victims since its first known activity in June 2025. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.
How many victims has Kawa4096 attacked?
Kawa4096 has claimed 17 victims in our database, representing 0.1% of all tracked ransomware attacks. The most targeted countries are United States, Japan, Germany.
Which countries does Kawa4096 target?
Kawa4096 has attacked organizations in 3 countries. The top targeted countries are: United States, Japan, Germany.
Which industries does Kawa4096 target?
Kawa4096 most frequently targets the Healthcare, Financial Services, Public Sector sectors based on victim disclosures in our database.
Is Kawa4096 still active?
Kawa4096's most recent victim disclosure in our database was on July 29, 2025. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.