216.73.217.22

KAWA4096’s Ransomware Tide: Rising Threat With Borrowed Styles

· Published 18/07/2025 07:36 · Modified 18/07/2025 08:51

Export JSON

Essential information

Published
18/07/2025 07:36
Modified
18/07/2025 08:51
Tags
2025-07-18 data leak site kawa4096 multithreading ransomware shadow copy deletion
Related entities
1 intrusion sets (apt), 9 techniques (mitre), 1 malware, 2 others

Description

, a new that emerged in June 2025, has claimed at least 11 victims, primarily targeting the United States and Japan. The malware features a leak site mimicking the Akira group's style and a ransom note format similar to Qilin's. employs , semaphores for synchronization, and can encrypt files on shared network drives. It terminates specific services and processes, deletes shadow copies, and utilizes a configuration loaded from its binary. The 's encryption process involves file scanning, skipping certain files and directories, and using a shared queue for efficient processing. It also changes file icons and can modify the desktop wallpaper. The group's tactics appear to be aimed at boosting visibility and credibility by imitating established operations.

External references