Kawabunga, Dude, You’ve Been Ransomed!
ID: 3a9e6214-555b-5d3f-99c3-5c405f4c4226
STIX ID: report--3a9e6214-555b-5d3f-99c3-5c405f4c4226
Feed Name: Huntress Blog
KawaLocker (KAWA4096) ransomware was deployed in a compromised environment after RDP access; the attacker used HRSword and other tooling to identify and disable security products, installed drivers, propagated via PsExec, and executed e.exe to encrypt files on the E: volume. Huntress captured event log evidence, recovered the ransom note and encrypted file list, observed post-encryption cleanup (shadow copy deletion, event log clearing, self-deletion), and published IOCs and TTPs used to detect and remediate similar incidents.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
