kawa4096
Kawa4096 is a ransomware group that emerged in June 2025, targeting multinational corporations across finance, education, and services sectors primarily in the US and Japan, using partial-encryption (25% of each file chunk) with Salsa20 and a leak site styled after Akira's retro terminal aesthetic, claiming at least 11 victims.
| Name | Country | Sector | Date |
|---|---|---|---|
| ********.org | US | Not Found | 2025-07-29T07:17:47.848122+00:00 |
| **********.net | US | Not Found | 2025-07-27T23:49:12.966228+00:00 |
| **********.com | US | Not Found | 2025-07-27T09:44:51.929187+00:00 |
| icmconv.com | US | Not Found | 2025-07-22T05:29:08.072026+00:00 |
| carestlhealth.org | US | Healthcare | 2025-07-22T05:28:43.024013+00:00 |
| sbamh.org | US | Healthcare | 2025-07-22T04:50:42.623188+00:00 |
| gatewaycsb.org | US | Public Sector | 2025-07-07T14:54:08.919538+00:00 |
| heimhaus.de | DE | Not Found | 2025-07-07T11:55:03.194176+00:00 |
| tokiomarine-nichido.co.jp | JP | Financial Services | 2025-07-01T13:18:24.568775+00:00 |
| www.ogr-jp.com | JP | Not Found | 2025-07-01T13:18:00.020188+00:00 |
| www.malonebailey.com | US | Financial Services | 2025-06-30T21:32:27.996409+00:00 |
| **********-*******.co.jp | JP | Not Found | 2025-06-30T21:32:01.626923+00:00 |
| *************.org | — | Not Found | 2025-06-30T21:31:58.553155+00:00 |
| Morningsideservices | US | Not Found | 2025-06-27T14:17:27.664113+00:00 |
| ******.de | DE | Not Found | 2025-06-27T14:16:55.184159+00:00 |
| ******.com | US | Not Found | 2025-06-27T14:16:23.437641+00:00 |
| ******.org | US | Not Found | 2025-06-27T14:15:37.498770+00:00 |
Data from ransomware.live