Kazu is a financially motivated ransomware group targeting the healthcare and government sectors.
Analyst brief
Kazu is a financially motivated ransomware group primarily targeting the healthcare and government sectors. The group employs a double extortion model, exfiltrating sensitive data through techniques like exploiting unpatched vulnerabilities and credential reuse. Defenders should focus on enforcing multi-factor authentication on remote access services and ensuring timely patching of critical vulnerabilities.
Kazu
unknown
Kazu is a financially motivated ransomware group known for employing a double extortion model, targeting sectors such as healthcare and government. The group has claimed responsibility for multiple high-profile breaches, including those of Manage My Health and the Defensoría del Pueblo de Colombia, exfiltrating sensitive data through techniques like exploiting unpatched vulnerabilities and credential reuse. Kazu has demanded ransoms ranging from $60,000 to $500,000, threatening public disclosure of stolen data if payments are not made. Their operations have primarily focused on entities in Latin America, Asia, and the Middle East, with a notable presence on dark web leak sites.