Ransomware Intelligence

Ransomware needs a way in. Stolen credentials are the cheapest one.

Check Your Exposure

zawoo Ransomware Group

Ransomware group profile

17Victims
41Impact score

Description

Zawoo is a financially motivated ransomware group that emerged in August 2026, targeting small to mid-sized enterprises. The group uses hands-on-keyboard methods and has an extortion data leak site for publishing victim details. It targets organizations mainly in German-speaking Europe, North America, South America, and the Asia-Pacific region.

Key insights

  • Targets small to mid-sized enterprises across various sectors, primarily in German-speaking regions and globally.
  • Gains unauthorized access through compromised VPN credentials without multi-factor authentication.
  • Utilizes custom PowerShell scripts for credential harvesting and data collection.
  • Encrypts files using ransomware that renames them to hexadecimal strings.
  • Employs tactics like lateral movement via Remote Desktop Protocol and PsExec.
  • Maintains a Tor leak site to threaten victims with public exposure unless ransoms are paid.

Threat Level & Status Breakdown

For zawoo · Based on incidents in selected period

2.1threat level
Aggressiveness4.3/ 10
Lethality0/ 10
Criticality2/ 10

Status Breakdown

Claimed100.0%17
First seenAug 2026
Last seenAug 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedSep 17, 2026

Recent activity

Monthly attack count for zawoo in the selected period

17Total attacks
17peak in Aug
17avg / month
Aug05101520

No intelligence data for this group.

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for zawoo

Credential Access

T1003

OS Credential Dumping

Defense Evasion

T1562

Impair Defenses

Execution

T1059

Command and Scripting Interpreter

Impact

T1486

Data Encrypted for Impact

T1490

Inhibit System Recovery

Lateral Movement

T1021

Remote Services

T1021.001

Remote Desktop Protocol

Other

T1203

T1203

Persistence

T1078

Valid Accounts

T1547

Boot or Logon Autostart Execution

Victims(17)

GermanyRetail & E-Commercefes-sport.de
Claimed
18 days ago
GermanyTechnologyvectorsoft.de
Claimed
20 days ago
GermanyTechnologybotec.com
Claimed
20 days ago
CanadaOtheracqbuilt.com
Claimed
20 days ago
BrazilManufacturingfrm.ind.br
Claimed
20 days ago
AustriaHospitalityn-tree.com
Claimed
20 days ago
GermanyHospitalityberghotel-oberhof.de
Claimed
20 days ago
Czech RepublicManufacturingkdynium.cz
Claimed
20 days ago
GermanyOtherrsk-immobilien.de
Claimed
20 days ago
GermanyManufacturingmontronix.de
Claimed
20 days ago
GermanyEducationfes-sport.de
Claimed
19 days ago
GermanyOtherwinterdienst-berlin.com
Claimed
20 days ago
GermanyHealthcarehd-werkstaetten.de
Claimed
20 days ago
GermanyTechnologyng-engineering.de
Claimed
20 days ago
United StatesProfessional Servicesesopartnerscpa.com
Claimed
19 days ago
New ZealandTechnologyzenithtechnology.co.nz
Claimed
19 days ago
GermanyRetail & E-Commercehoerburger.de
Claimed
19 days ago