Kawabunga, Dude, You've Been Ransomed!
Essential information
- Published
- 15/08/2025 05:29
- Modified
- 15/08/2025 12:38
- Tags
- 2025-08-15 encryption hrsword kawa4096 kawalocker psexec ransomware rdp
- Related entities
- 5 observables, 1 intrusion sets (apt), 4 techniques (mitre), 3 malware
Description
A new ransomware variant called KawaLocker (KAWA4096) was recently observed in an attack. The threat actor gained initial access via RDP using a compromised account and employed various tools to disable security measures. HRSword, a monitoring tool, was deployed along with kernel drivers sysdiag.sys and hrwfpdr.sys. The attacker used PsExec to enable RDP on additional endpoints. KawaLocker ransomware was then deployed against the E:\ volume, encrypting files and leaving a ransom note. Post-encryption, the attacker deleted Volume Shadow Copies, cleared Windows Event Logs, and removed the ransomware executable. The incident highlights the importance of detecting and remediating such attacks promptly.