Kawabunga, Dude, You’ve Been Ransomed!

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

Huntress analysts documented a KawaLocker (KAWA4096) ransomware attack observed on August 8, 2025. The threat actor gained initial access via RDP using a compromised account, then deployed HRSword — a tool from China-based Huorong Network Technology — along with kernel drivers (sysdiag.sys, hrwfpdr.sys) to disable security tooling. After using Advanced Port Scanner for network enumeration and PsExec to enable RDP on additional hosts, the attacker deployed the ransomware against the E:\ volume. Post-encryption cleanup included deleting Volume Shadow Copies, clearing Windows Event Logs, and self-deleting the ransomware binary. KawaLocker, first seen in June 2025, borrows visual elements from Akira and Qilin ransomware families. Huntress contained the attack before it spread to other endpoints. Indicators of compromise including file extensions, driver names, and executable names are provided.

5m read timeFrom huntress.com
Post cover image
Table of contents
What is KawaLocker ransomware?Initial access and HRSwordKawaLocker ransomware deploymentDetection breadcrumbs for KawaLockerIndicators of Compromise
1 Impression