Kazu
Ransomware Group Profile
Overview
Kazu is an emerging ransomware group active since September 2025 that employs double-extortion tactics, targeting government, healthcare, and financial organizations primarily in Southeast Asia, the Middle East, and Latin America, with notable claimed breaches including Dubai's Ports, Customs and Free Zone Corporation with 1.94 TB exfiltrated.
Dark Web Infrastructure (5)
6czlbd2jfiy6765fbnbnzuwuqocg57ebvp3tbm35kib425k4qnmiiiqd.onion
kazu7japbm72xaxqnjhajlvkuo4czf2q5ye7ucc4fmyjpgunc6ggezyd.onion
kazusemtykpxnnosg3gp56spcdkg7tro6ozei7ikamdgnwpwpbwagbyd.onion
kazuuyscnd6emsrzkpelzxgxvro2wgrngku4g7btuunsandnjv5f52ad.onion
kazu2x7vux5gmbrrqnbujbpe5njyqua5ulixubfcf64qae7qbvce4gqd.onion
Activity Timeline
First Seen2026
Last Seen2026
Leak Sites5
Quick Actions