Kawa4096 is a ransomware group since June 2025 targeting finance, education, and services sectors with partial-encryption.
Analyst brief
Kawa4096 is a ransomware group that emerged in June 2025. It targets multinational corporations across finance, education, and services sectors, primarily in the US and Japan. The group uses partial-encryption tactics with Salsa20, encrypting only 25% of each file chunk, and operates a leak site styled after Akira's retro terminal aesthetic. Defenders should focus on file integrity monitoring against this novel partial-encryption approach and enhance email security to counter targeted phishing campaigns aimed at the mentioned sectors.
kawa4096
KaWaLocker
crime
Kawa4096 is a ransomware group that emerged in June 2025, targeting multinational corporations across finance, education, and services sectors primarily in the US and Japan, using partial-encryption (25% of each file chunk) with Salsa20 and a leak site styled after Akira's retro terminal aesthetic, claiming at least 11 victims.