HomeSecurityBeware! Ransomware Kawa4096 attacks multinationals

Beware! Kawa4096 Ransomware Attacks Multinationals

A new, sophisticated ransomware group, named Kawa4096, has emerged and is targeting multinationals in various sectors.

Kawa4096 Ransomware

First detected in June 2025, Kawa4096 has already established itself as a significant threat to businesses in the sectors financial, education, and service, with a particular focus on victims in Japan and the United States.

Its operational sophistication suggests well-coordinated cybercriminal activities with the potential to have a wide-ranging impact across multiple countries in an extremely short period of time. The Kawa4096 ransomware operation demonstrates advanced capabilities through the implementation of methodologies double extortion (combining system encryption with data theft to maximize pressure on victims).

See also: Hackers target ICS computers with malicious scripts

The group also has a dedicated data leakage platform, where it systematically reveals victims' information, creating additional pressure to comply with the ransom payment.

The structure of Kawa4096's operation reveals meticulous planning, with personalized links for each victim to control access to data and maintain organized communication channels throughout the extortion process.

Kawa4096: How does it stand out from other ransomware?

ASEC analysts noted that the group’s malware incorporates several features that differentiate it from conventional ransomware families. For example, it automatically re-executes with the -all argument when launched without parameters, ensuring complete file encryption on target systems. In addition, it creates a unique mutex named “ SAY_HI_2025 ” using the CreateMutexA API. This prevents duplicate executions and potential system conflicts during the encryption process.

Beware! Kawa4096 Ransomware Attacks Multinationals

The ransomware's configuration management system uses built-in resource blocks containing 17 distinct fields that control encryption behavior. These configurations include extensive blacklists for file extensions, directories , and specific filenames to maintain system stability while maximizing damage. Critical system files such as .exe, .dll, .sys, and core Windows components such as boot.ini and desktop.ini are intentionally blacklisted to maintain system functionality and, by extension, negotiation capabilities.

See also: New Botnet Exploits DNS Misconfiguration

Advanced encryption methods

Kawa4096 uses techniques partial encryption to optimize speed and efficiency while still being destructive. The malware divides target files into 64KB chunks and encrypts only 25% of each file, significantly reducing encryption time while rendering the files completely unusable. This selective approach proves particularly effective against databases, documents, and multimedia, where partial corruption of headers or indexes renders entire files inaccessible.

The encryption process uses the Salsa20 algorithm, with encrypted files receiving extensions in the format [original_filename].[extension].[9_random_characters]. For files larger than 10MB, the ransomware applies strong partial encryption patterns, while smaller files receive full or weak partial encryption. This adaptive approach demonstrates the team’s understanding of optimizing system performance and maximizing the impact on victims.

See also: BlackLock Ransomware targets Windows, Linux & VMware ESXi

The ransomware systematically terminates critical processes, including database servers, office applications, and backup services (to unlock files for encryption). Targeted processes include sqlservr.exe, excel.exe, firefox.exe, outlook.exe, and many other applications that could interfere with the encryption process or provide recovery mechanisms for victims.

Beware! Kawa4096 Ransomware Attacks Multinationals

Ransomware protection

  • Stay up to date on the latest ransomware trends and tactics used by attackers
  • Implement multi-factor authentication (MFA) for all user accounts
  • Enable firewall on all devices connected to your network
  • Keep sensitive data encrypted
  • Update all your devices and systems with the latest security patches
  • Conduct regular security audits and penetration testing
  • Use strong, unique passwords and change them regularly.
  • Limit user access to only necessary systems and information
  • Consider using  email security solutions for additional protection against phishing attacks
  • Have a recovery plan to quickly restore systems in the event of an attack
  • Enable the display of file extensions
  • Invest in advanced protection solutions
  • Use sandboxing for email attachments
  • Keep backup copies of your data
Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS