kawa4096
Ransomware Group Profile
Overview
Kawa4096 is a ransomware group that emerged in June 2025, targeting multinational corporations across finance, education, and services sectors primarily in the US and Japan, using partial-encryption (25% of each file chunk) with Salsa20 and a leak site styled after Akira's retro terminal aesthetic, claiming at least 11 victims.
Dark Web Infrastructure (1)
kawasa2qo7345dt7ogxmx7qmn6z2hnwaoi3h5aeosupozkddqwp6lqqd.onion
Activity Timeline
First SeenUnknown
Last SeenUnknown
Leak Sites1
Quick Actions