Kawa4096 is a ransomware group first observed in late June 2025 and associated with deployment of the KaWaLocker ransomware. It has been identified as an emerging entrant in the ransomware ecosystem and was later noted among prominent ransomware variants in Q3 2025. Early reporting links the group to attacks against organizations in Japan, including at least two Japanese companies, and victim claims also include healthcare and other enterprises. KaWaLocker is a Windows ransomware family that loads configuration data from the binary resource section and supports customizable execution options, including multithreaded encryption and directory-specific targeting. Reported functionality includes creation of custom encrypted-file extensions and icons, deletion of shadow copies and event logs to hinder recovery, and possible self-deletion. The malware uses Salsa20-based file encryption and later evolved into a 2.0 variant with additional features such as file-name obfuscation. Its ransom notes threaten publication of stolen data, indicating use of double-extortion rather than encryption alone. Available reporting supports Kawa4096 as a financially motivated extortion actor focused on ransomware operations. Observed behavior supports capabilities in initial access, defense evasion, exfiltration, and post-compromise impact through encryption and extortion. Japan-focused reporting indicates activity against small and medium-sized enterprises, with manufacturing a prominent ransomware target in that environment, while public victim claims also include healthcare organizations. Some reporting suggests the group emerged alongside other new ransomware brands that may have absorbed tooling or personnel from defunct operations, but such lineage is not established at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
KAWA4096 is an emerging ransomware variant that entered the top five by market share in Q3 2025.
Named as a new ransomware variant/gang emerging in 2024 and associated with victim claims posted in June 2024.
Kawa4096 is a newly emerged ransomware group as of late June 2025, immediately targeting Japanese companies. It deploys a custom ransomware called KaWaLocker (and KaWaLocker 2.0), which features configurable encryption, custom file extensions, and double extortion tactics.
Ransomware/extortion actor targeting healthcare providers with sizable data-theft claims and leak-site listings.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.