Zawoo is a financially motivated ransomware group that emerged in August 2026, targeting small to mid-sized enterprises. The group uses hands-on-keyboard methods and has an extortion data leak site for publishing victim details. It targets organizations mainly in German-speaking Europe, North America, South America, and the Asia-Pacific region.
Key insights
•Targets small to mid-sized enterprises across various sectors, primarily in German-speaking regions and globally.
•Gains unauthorized access through compromised VPN credentials without multi-factor authentication.
•Utilizes custom PowerShell scripts for credential harvesting and data collection.
•Encrypts files using ransomware that renames them to hexadecimal strings.
•Employs tactics like lateral movement via Remote Desktop Protocol and PsExec.
•Maintains a Tor leak site to threaten victims with public exposure unless ransoms are paid.