// THREAT ACTOR
KAWA_
DormantKAWA is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem — file encryption combined with the threat of stolen-data publication on a public leak site — and continues to post fresh victim claims as part of an ongoing extortion campaign.
For Ransomnews editorial coverage of KAWA — incident write-ups, attribution notes, and additional context — see the Threat Groups archive or run a site search.
Victims by year
- 2025 11
Leak site mirrors
1 mirror tracked, 0 currently reachable. These are criminal-infrastructure URLs — links are deliberately not provided.
-
kawasa2qo7345dt7ogxmx7qmn6z2hnwaoi3h5aeosupozkddqwp6lqqd.onionKawa4096 snapshot · 2025-08-16 06:08
Recent victims
The 50 most recent victims claimed by KAWA. Total in the index: 11.
| Date listed | Victim | Description |
|---|---|---|
| 2025-07-08 | US:*************.org | *************.org |
| 2025-07-07 | DE:heimhaus.de | www.heimhaus.de HEIM & HAUS ist das führende Direktvertriebsunternehme… |
| 2025-07-07 | US:gatewaycsb.org | Published: 2025-06-25 gatewaycsb.org Community Service Boards (CSBs… |
| 2025-07-07 | JP:tokiomarine-nichido.co.jp | Published: 2025-06-26 tokiomarine-nichido.co.jp Tokio Marine & Nic… |
| 2025-07-07 | JP:www.ogr-jp.com | Published: 2025-06-28 www.ogr-jp.com Oriental Guard Research Inc. … |
| 2025-06-30 | US:www.malonebailey.com | Published: 2025-06-24 www.malonebailey.com We’re One of the Big Guy… |
| 2025-06-27 | US:******.org | US:******.org ******.org 2025-06-25 content |
| 2025-06-27 | www.******.com | US:******.com www.******.com 2025-06-24 content |
| 2025-06-27 | www.******.de | DE:******.de www.******.de 2025-06-22 content |
| 2025-06-27 | US:******.com | ******.com |
| 2025-06-27 | US:Morningsideservices | Published: 2025-06-20 Morningside has been changing the lives of in… |