A new, sophisticated ransomware group, named Kawa4096, has emerged and is targeting multinationals in various sectors.

First detected in June 2025, Kawa4096 has already established itself as a significant threat to businesses in the sectors financial, education, and service, with a particular focus on victims in Japan and the United States.
Its operational sophistication suggests well-coordinated cybercriminal activities with the potential to have a wide-ranging impact across multiple countries in an extremely short period of time. The Kawa4096 ransomware operation demonstrates advanced capabilities through the implementation of methodologies double extortion (combining system encryption with data theft to maximize pressure on victims).
See also: Hackers target ICS computers with malicious scripts
The group also has a dedicated data leakage platform, where it systematically reveals victims' information, creating additional pressure to comply with the ransom payment.
The structure of Kawa4096's operation reveals meticulous planning, with personalized links for each victim to control access to data and maintain organized communication channels throughout the extortion process.
Kawa4096: How does it stand out from other ransomware?
ASEC analysts noted that the group’s malware incorporates several features that differentiate it from conventional ransomware families. For example, it automatically re-executes with the -all argument when launched without parameters, ensuring complete file encryption on target systems. In addition, it creates a unique mutex named “ SAY_HI_2025 ” using the CreateMutexA API. This prevents duplicate executions and potential system conflicts during the encryption process.

The ransomware's configuration management system uses built-in resource blocks containing 17 distinct fields that control encryption behavior. These configurations include extensive blacklists for file extensions, directories , and specific filenames to maintain system stability while maximizing damage. Critical system files such as .exe, .dll, .sys, and core Windows components such as boot.ini and desktop.ini are intentionally blacklisted to maintain system functionality and, by extension, negotiation capabilities.
See also: New Botnet Exploits DNS Misconfiguration
Advanced encryption methods
Kawa4096 uses techniques partial encryption to optimize speed and efficiency while still being destructive. The malware divides target files into 64KB chunks and encrypts only 25% of each file, significantly reducing encryption time while rendering the files completely unusable. This selective approach proves particularly effective against databases, documents, and multimedia, where partial corruption of headers or indexes renders entire files inaccessible.
The encryption process uses the Salsa20 algorithm, with encrypted files receiving extensions in the format [original_filename].[extension].[9_random_characters]. For files larger than 10MB, the ransomware applies strong partial encryption patterns, while smaller files receive full or weak partial encryption. This adaptive approach demonstrates the team’s understanding of optimizing system performance and maximizing the impact on victims.
See also: BlackLock Ransomware targets Windows, Linux & VMware ESXi
The ransomware systematically terminates critical processes, including database servers, office applications, and backup services (to unlock files for encryption). Targeted processes include sqlservr.exe, excel.exe, firefox.exe, outlook.exe, and many other applications that could interfere with the encryption process or provide recovery mechanisms for victims.

Ransomware protection
- Stay up to date on the latest ransomware trends and tactics used by attackers
- Implement multi-factor authentication (MFA) for all user accounts
- Enable firewall on all devices connected to your network
- Keep sensitive data encrypted
- Update all your devices and systems with the latest security patches
- Conduct regular security audits and penetration testing
- Use strong, unique passwords and change them regularly.
- Limit user access to only necessary systems and information
- Consider using email security solutions for additional protection against phishing attacks
- Have a recovery plan to quickly restore systems in the event of an attack
- Enable the display of file extensions
- Invest in advanced protection solutions
- Use sandboxing for email attachments
- Keep backup copies of your data
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
