HackerFeeds
All ransomware groups

kawa4096

17 tracked victims
·first seen 2025-06-19·last activity 2025-07-28

Group profile

Kawa4096 is a ransomware group that emerged in June 2025, targeting multinational corporations across finance, education, and services sectors primarily in the US and Japan, using partial-encryption (25% of each file chunk) with Salsa20 and a leak site styled after Akira's retro terminal aesthetic, claiming at least 11 victims.

Recent victims

DateWebsite / victimSectorCountry
2025-07-28
*
********.org
Not FoundUS
2025-07-27
*
**********.net
Not FoundUS
2025-07-27
*
**********.com
Not FoundUS
2025-06-19
icmconv.com
icmconv.comicmconv.com
Not FoundUS
2025-06-28
carestlhealth.org
carestlhealth.orgcarestlhealth.org
HealthcareUS
2025-07-20
sbamh.org
sbamh.orgsbamh.org
HealthcareUS
2025-06-25
gatewaycsb.org
gatewaycsb.orggatewaycsb.org
Public SectorUS
2025-06-22
heimhaus.de
heimhaus.deheimhaus.de
Not FoundDE
2025-06-26
tokiomarine-nichido.co.jp
tokiomarine-nichido.co.jptokiomarine-nichido.co.jp
Financial ServicesJP
2025-06-28
ogr-jp.com
www.ogr-jp.comwww.ogr-jp.com
Not FoundJP
2025-06-24
malonebailey.com
www.malonebailey.commalonebailey.com
Financial ServicesUS
2025-06-26
*
**********-*******.co.jp
Not FoundJP
2025-06-28
*
*************.org
Not Found
2025-06-20
morningsideservices.com
MorningsideservicesMorningsideservices.com
Not FoundUS
2025-06-22
*
******.de
Not FoundDE
2025-06-24
*
******.com
Not FoundUS
2025-06-25
*
******.org
Not FoundUS