216.73.217.22

Kawabunga, Dude, You've Been Ransomed!

· Published 15/08/2025 05:29 · Modified 15/08/2025 12:38

Export JSON

Essential information

Published
15/08/2025 05:29
Modified
15/08/2025 12:38
Tags
2025-08-15 encryption hrsword kawa4096 kawalocker psexec ransomware rdp
Related entities
5 observables, 1 intrusion sets (apt), 4 techniques (mitre), 3 malware

Description

A new variant called () was recently observed in an attack. The threat actor gained initial access via using a compromised account and employed various tools to disable security measures. , a monitoring tool, was deployed along with kernel drivers sysdiag.sys and hrwfpdr.sys. The attacker used to enable on additional endpoints. was then deployed against the E:\ volume, encrypting files and leaving a ransom note. Post-, the attacker deleted Volume Shadow Copies, cleared Windows Event Logs, and removed the executable. The incident highlights the importance of detecting and remediating such attacks promptly.

External references