Kawa4096

Inactive
Kawa4096 is a ransomware group that emerged in June 2025, targeting multinational corporations across finance, education, and services sectors primarily in the US and Japan, using partial-encryption (25% of each file chunk) with Salsa20 and a leak site styled after Akira's retro terminal aesthetic, claiming at least 11 victims.
17 Victims
Jun 19, 2025 First Discovered
Jul 28, 2025 Last Discovered
415 Days Inactive
0% Infostealer
0/1 Sites Online
Known Locations (1)
Kawa4096
kawasa2qo7345dt7ogxmx7qmn6z2hnwaoi3h5aeosupozkddqwp6lqqd.onion
Victims (17)

Detailed victim list temporarily unavailable

This group has 17 victims. The victim list API is currently responding slowly for this dataset. Country, sector, and infostealer breakdowns are not available at this time. Basic stats (victim count, first/last seen) are shown above from a faster data source.