Ransomware Intelligence

kazu

Ransomware group profile

43Victims
RussiaSource country
70Impact score

Description

kazu is a financially motivated ransomware and data extortion group that emerged around mid-2025, notably targeting government agencies and healthcare providers. They utilize sophisticated tactics for initial access and data exfiltration, employing a double-extortion model to coerce victims into paying ransoms.

Key insights

  • Targets include government agencies, public-sector institutions, and healthcare providers.
  • Initial access is typically gained through exploiting RDP services and unpatched web applications.
  • The group uses SmokeLoader as the initial loader to deliver ransomware payloads.
  • Employs a double-extortion tactic, exfiltrating data before encrypting files.
  • Ransom demands range from $60,000 to $500,000, with threats to publish stolen data.

Threat Level & Status Breakdown

For kazu · Based on incidents in selected period

3.6threat level
Aggressiveness7/ 10
Lethality0/ 10
Criticality3.9/ 10

Status Breakdown

Claimed7.0%3
First seenNov 2025
Last seenMay 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 2, 2026

Recent activity

Monthly attack count for kazu in the selected period

43Total attacks
35peak in Nov
10.8avg / month
↓ 33 vs first month
NovDecJanMay09182736

No intelligence data for this group.

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for kazu

Other

T1486

T1486

T1490

T1490

T1078

T1078

T1059

T1059

T1566.001

T1566.001

T1133

T1133

T1190

T1190

T1021

T1021

T1562

T1562

T1046

T1046

Victims(43)

CompanyDomainCountryIndustryStatusDiscovered
Databases
Claimed
6 days ago
Ransom
Claimed
6 days ago
zHealthEHR — Practice Management Software for Chiropractic & Wellness Clinicszhealthehr.comUS United StatesTechnology
Unknown
4 months ago
MyVetemyvete.comES SpainProfessional Services
Unknown
5 months ago
ManageMyHealth - New Zealandmanagemyhealth.co.nzNZ New ZealandHealthcare
Unknown
5 months ago
Saudi Iconsaudi-icon.comSA Saudi ArabiaOther
Unknown
5 months ago
Leadway Assuranceleadwayhealth.comNG NigeriaFinancial Services
Unknown
6 months ago
CT Dent Ltdct-dent.co.ukGB United KingdomHealthcare
Unknown
6 months ago
GOBIERNO DE GUANAJUATOMX MexicoGovernment & Defense
Unknown
7 months ago
Venezuela’s Cooperative Registration and Management SystemVE VenezuelaGovernment & Defense
Unknown
7 months ago
Official Website of the Municipality of QuerétaroMX MexicoGovernment & Defense
Unknown
7 months ago
Official Website of Vehicle Emissions Control (VEC Mexico)MX MexicoManufacturing
Unknown
7 months ago
National Entrepreneur System of MexicoMX MexicoGovernment & Defense
Unknown
7 months ago
Guadalajara Social Assistance AgencyMX MexicoGovernment & Defense
Unknown
7 months ago
Nepal official Police WebsiteNP NepalGovernment & Defense
Unknown
7 months ago
Saudi Arabia Gov - Taif Municipality PortalSA Saudi ArabiaGovernment & Defense
Unknown
7 months ago
Official Platform for Employability Certification in MauritaniaMR MauritaniaEducation
Unknown
7 months ago
Bolivian Military Social Security Corporation – COSSMILBO BoliviaGovernment & Defense
Unknown
7 months ago
Ministry of Health – Government of Sri LankaLK Sri LankaGovernment & Defense
Unknown
7 months ago
Zacatecas State Department of EducationMX MexicoEducation
Unknown
7 months ago

Page 1 of 3