logo

Kawabunga, Dude, You’ve Been Ransomed!

ID: 3a9e6214-555b-5d3f-99c3-5c405f4c4226

STIX ID: report--3a9e6214-555b-5d3f-99c3-5c405f4c4226

Feed Name: Huntress Blog

Threat Score
70/100

Date Published: 2025-08-14

Date Updated: 2026-04-28

...
...

KawaLocker (KAWA4096) ransomware was deployed in a compromised environment after RDP access; the attacker used HRSword and other tooling to identify and disable security products, installed drivers, propagated via PsExec, and executed e.exe to encrypt files on the E: volume. Huntress captured event log evidence, recovered the ransom note and encrypted file list, observed post-encryption cleanup (shadow copy deletion, event log clearing, self-deletion), and published IOCs and TTPs used to detect and remediate similar incidents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.