Ransomware Group intelligence
Kazu
ActiveTrack Kazu with 29 published victims and 1 known leak locations in a single intelligence view.
Overview
Kazu is tracked by Breach House as a ransomware group with 29 published victims.
United States is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Up checked 56m ago | 6czlbd2jfiy6765fbnbnzuwuqocg57ebvp3tbm35kib425k4qnmiiiqd.onion |
Top Activity Sectors (9)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Kazu, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: kazu executes PowerShell scripts to deliver ransomware payloads and manipulate system processes.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: kazu adds malicious registry run keys to ensure ransomware execution upon system reboot.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: kazu disables antivirus tools and security software via command-line utilities to evade detection.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: kazu encodes victim data with symmetric keys before exfiltration to hide stolen healthcare records.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: kazu deletes Volume Shadow Copies and backup directories via vssadmin to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: kazu discovers remote hosts using native API calls to map internal network structure before targeting.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1135 Network Share Discovery Discovery
What they do: kazu scans network shares using SMB tools to identify victim files for encryption.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: kazu moves laterally through SMB shares to encrypt files across networked medical and communication systems.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: kazu encrypts critical patient and operational files using custom ransomware binaries for impact.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: kazu halts backup services and system recovery processes to maximize operational disruption.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (29)
Search, filter and paginate the victim timeline for Kazu. Showing 1–29 of 29.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Redacted id32096 View details | — | — | ||
|
redacted.com operates within the cybersecurity and digital services sector, providing protective and analytical offerings focused on threat monitoring and incident response support. As a ransomware victim, the entity is documented within this threat-intelligence index due to its association with the threat actor kazu. The listing type identifies redacted.com specifically as a ransomware victim linked to this actor profile. This entry serves as a neutral reference point for cataloging affected entities and their connections to identified threat actors in cyber threat intelligence reporting. |
|||||
| Ransomware | Redacted id32096 View details | — | — | ||
|
Soon |
|||||
| Ransomware | PappyJoe: Healthcare Management System id32038 View details | United States | Retail / E-commerce | — | |
|
pappyjoe.com operates within the Retail and E-commerce sector, with operations based in the United States. The entity serves retail and online commerce functions, providing digital commerce services to customers and managing business operations within this high-exposure industry. It is cataloged in the threat-intelligence index specifically as a ransomware victim, with the associated threat actor identified as kazu. This listing reflects the cybersecurity context surrounding the entity without disclosing unverified incident details. The record supports threat-aware monitoring for sector-relevant security professionals and defenders tracking ransomware activity. |
|||||
| Ransomware | PappyJoe: Healthcare Management System id32038 View details | United States | Retail / E-commerce | — | |
|
PappyJoe is an India-based healthcare technology company that provides a cloud-based practice management platform for clinics, hospitals, and healthcare professionals. The platform helps manage appointments, electronic medical records (EMR), billing, prescriptions, patient communication, and administrative tasks in one system |
|||||
| Ransomware | Instituto Ferrero de Neurología y Sueño id32039 View details | Argentina | Finance / Legal / Insurance | — | |
|
ifn.com.ar operates within the Finance, Legal, and Insurance sectors and is located in the country AR. The entity functions as a commercial organization providing domain-based services aligned with its declared industry verticals. According to the threat-intelligence index, ifn.com.ar is cataloged as a ransomware victim associated with threat actor kazu. This listing reflects its inclusion in the ransomware victim segment linked to kazu's activity profile. The description remains factual and neutral, focusing on the entity's sector, geographic context, and verified association without speculating on breach details. |
|||||
| Ransomware | Instituto Ferrero de Neurología y Sueño id32039 View details | Argentina | Finance / Legal / Insurance | — | |
|
Instituto Ferrero de Neurología y Sueño (IFN) is a specialized medical center in Argentina that focuses on the diagnosis and treatment of neurological and sleep disorders. It provides services such as neurology consultations, sleep studies, diagnostic testing, and personalized treatment plans. Using advanced medical technology and a team of specialists, IFN helps patients receive comprehensive care for conditions affecting the brain, nervous system, and sleep health. |
|||||
| Ransomware | Brazil Mobilemed: Cloud PACS Platform id32040 View details | Brazil | Healthcare / Pharma | — | |
|
mobilemed.com.br operates within the healthcare and medicine sector based in Brazil. The entity represents a healthcare organization whose infrastructure was identified within the threat-intelligence index under the ransomware victim classification. This listing is associated with threat actor kazu, reflecting the security event correlated to the entity in the intelligence dataset. The description avoids speculative claims regarding data stolen, ransom demands, or breach confirmation, focusing solely on the verified catalog classification and contextual metadata. Its inclusion underscores the vulnerability landscape within Brazilian healthcare systems targeted by identified cyber threats. |
|||||
| Ransomware | Brazil Mobilemed: Cloud PACS Platform id32040 View details | Brazil | Healthcare / Pharma | — | |
|
Mobilemed is a Brazil-based health technology company that provides a cloud-based PACS (Picture Archiving and Communication System) for radiologists, hospitals, and diagnostic imaging centers. Its platform enables healthcare professionals to securely store, access, manage, and share medical images and diagnostic reports from anywhere, supporting teleradiology and improving workflow efficiency. |
|||||
| Ransomware | Canada Yocale: Appointment Management System id32041 View details | Canada | IT | — | |
|
www.yocale.com operates within the IT sector and is a Canadian entity cataloged in this threat-intelligence index as a ransomware victim. The listing associates this organization with the threat actor kazu, reflecting its inclusion in intelligence records concerning cyber incidents affecting technology-focused businesses. Catalog entries of this nature provide structured visibility into entities impacted by malicious activity, supporting risk assessment and threat-response workflows for analysts and security teams monitoring ransomware campaigns. The description remains factual and neutral, focusing on the entity's classification, geographic context, sector relevance, and verified association with the specified threat actor. |
|||||
| Ransomware | Canada Yocale: Appointment Management System id32041 View details | Canada | IT | — | |
|
Yocale is a cloud-based business management platform that helps appointment-based businesses streamline their daily operations. Founded in Canada, the platform is used by healthcare providers, beauty salons, wellness centers, and other service businesses to manage appointments, client records, payments, and communications in one centralized system. |
|||||
| Ransomware | PawlyClinic: Digital Veterinary Care Platform id32042 View details | United States | Healthcare / Pharma | — | |
|
www.pawlyclinic.com operates within the United States healthcare and medicine sector, providing clinical services and patient care solutions. As a ransomware victim indexed in this threat-intelligence catalog, its inclusion reflects documented threat-actor activity targeting healthcare infrastructure. The entity serves as a reference point for understanding cybersecurity risks within medical organizations and the specific tactics employed by the kazu threat actor. This listing supports security professionals in monitoring vulnerabilities and developing defensive strategies against ransomware campaigns in sensitive sectors. |
|||||
| Ransomware | PawlyClinic: Digital Veterinary Care Platform id32042 View details | United States | Healthcare / Pharma | — | |
|
PawlyClinic is a digital veterinary care platform that connects pet owners with licensed veterinarians through online consultations, appointment booking, and in-clinic referrals. It provides a convenient way for users to access veterinary advice, manage pet health records, and receive treatment without always needing to visit a clinic physically. |
|||||
| Ransomware | Dr Akbar Niazi Teaching Hospital id32043 View details | Pakistan | Manufacturing / Engineering | — | |
|
www.anth.pk is an entity operating within the Manufacturing and Engineering sector located in Pakistan. The organization provides industrial and technical services aligned with its sector, though specific operational details are not disclosed here to maintain factual accuracy. This listing identifies www.anth.pk within a threat-intelligence catalog under the designation ransomware victim, associated with the threat actor kazu. The entry serves to document the entity's sector, geographic context, and cybersecurity relevance for analysts monitoring industrial-sector threats. It neutrally records the association without asserting unverified incident details such as data exfiltration scope, ransom demands, or confirmed breach evidence. |
|||||
| Ransomware | Dr Akbar Niazi Teaching Hospital id32043 View details | Pakistan | Manufacturing / Engineering | — | |
|
Dr. Akbar Niazi Teaching Hospital (ANTH) is a 500-bed tertiary care teaching hospital located in Islamabad, Pakistan. The hospital provides a wide range of healthcare services, including emergency care, surgery, cardiology, orthopedics, pediatrics, gynecology, oncology, diagnostic laboratory services, and specialized outpatient clinics. As a teaching hospital, ANTH is affiliated with medical education and training programs, supporting the development of future healthcare professionals |
|||||
| Ransomware | Centro Médico Especializado OSI: Healthcare Solutions id32044 View details | Mexico | Healthcare / Pharma | — | |
|
Centromedicoosi.com operates within the Healthcare and Medicine sector and is associated with the country Mexico. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, with the associated threat actor identified as kazu. The description reflects the entity's classification and contextual sector without asserting specific breach details, data exfiltration specifics, or confirmed incident outcomes. This entry serves to document the relationship between the organization, its operational sector, and the attributed threat actor within the intelligence framework. Centromedicoosi.com was listed as a ransomware victim associated with kazu. |
|||||
| Ransomware | Centro Médico Especializado OSI: Healthcare Solutions id32044 View details | Mexico | Healthcare / Pharma | — | |
|
Centro Médico Especializado OSI is a healthcare provider based in Peru that specializes in physical medicine, rehabilitation, physiotherapy, chiropractic care, and alternative medicine treatments. Founded in 1999 and headquartered in Lima, OSI has grown into one of the country's largest rehabilitation and physiotherapy networks, operating multiple clinics across the Lima metropolitan area. wellness network in Peru, focused on helping patients recover mobility, reduce pain, and improve their quality of life through specialized medical and therapeutic care. |
|||||
| Ransomware | Meducar: Telemedicine and Patient Management System id32045 View details | Brazil | Education | — | |
|
meducar.com operates within the Education sector and is based in Brazil, providing services aligned with educational institution needs. The entity is listed in this threat-intelligence index as a ransomware victim associated with threat actor kazu. This classification reflects documented threat activity targeting organizations within this sector and geographic region. No specific incident details such as data stolen, records compromised, ransom demands, or confirmed breach evidence are included per strict factual guidelines. The listing serves to catalog the relationship between meducar.com and the identified threat actor for cybersecurity monitoring and intelligence purposes. |
|||||
| Ransomware | Meducar: Telemedicine and Patient Management System id32045 View details | Brazil | Education | — | |
|
Meducar is a Latin American healthtech platform that provides software for doctors and clinics to manage medical appointments, electronic health records, and patient communication in one system. It helps healthcare professionals organize their daily practice by offering tools such as online scheduling, clinical history management, electronic prescriptions, and telemedicine services. |
|||||
| Ransomware | ConsultorioMovil: Telemedicine and Healthcare System id32046 View details | Mexico | Services | — | |
|
consultoriomovil.net operates within the Services sector and is associated with the country Mexico (MX). The entity functions as a digital service provider, with its domain reflecting consultoriomovil as a business identifier within the services industry. Within threat-intelligence indexing frameworks, consultoriomovil.net is cataloged specifically as a ransomware victim, with the associated threat actor identified as kazu. This listing type indicates its inclusion in records tracking organizations impacted by ransomware campaigns and their linked adversary activity. The description remains factual and neutral, focusing on the entity's classification, sector context, geographic attribution, and verified threat association without elaborating on unconfirmed incident details. |
|||||
| Ransomware | ConsultorioMovil: Telemedicine and Healthcare System id32046 View details | Mexico | Services | — | |
|
digital healthcare platform designed to help doctors, clinics, and medical professionals manage their daily operations more efficiently. It provides tools for scheduling patient appointments, maintaining electronic medical records, and conducting telemedicine consultations through online video or messaging. The platform also supports clinical documentation, patient communication, and administrative tasks, helping healthcare providers reduce paperwork and improve organization. Overall, ConsultorioMovil aims to simplify medical practice management and improve the way doctors interact with and care for their patients through a single, centralized system. |
|||||
| Ransomware | zHealthEHR — Practice Management Software for Chiropractic & Wellness Clinics id25820 View details | United States | Healthcare / Pharma | — | |
|
zHealthEHR is a cloud-based electronic health record (EHR) and practice management platform built primarily for chiropractors and other wellness providers. It combines clinical documentation, appointment scheduling, patient intake, billing, payments, and automated reminders into a single system, helping small to mid-size practices streamline daily operations. The platform focuses on ease of use, customizable SOAP notes, and patient engagement tools, allowing providers to reduce administrative workload and run their clinics more efficiently through a subscription-based software model. |
|||||
| Ransomware | MyVete id25464 View details | Spain | Healthcare / Pharma | — | |
|
MyVete is a veterinary software designed to help animal clinics and veterinary practices manage their operations more efficiently. The platform includes features for managing patient records, appointments, billing, and inventory, all in one system. MyVete allows veterinarians to track medical histories, schedule appointments, and send reminders for vaccinations or follow-up care. The software also includes tools for managing invoicing and payments, allowing clinics to accept payments through multiple methods, including credit cards and insurance claims. With its easy-to-use interface, MyVete streamlines administrative tasks, reducing time spent on paperwork and improving patient care. By providing real-time access to patient data and operational insights, MyVete helps veterinary practices improve efficiency and deliver better care to animals. |
|||||
| Ransomware | ManageMyHealth - New Zealand id25219 View details | New Zealand | Healthcare / Pharma | — | |
|
ManageMyHealth is a New Zealand-based online platform that enables individuals to conveniently manage their health and well-being by providing secure access to their medical records and communication with healthcare providers. The platform allows users to view test results, manage prescriptions, schedule appointments, and track their health history from any device. It aims to improve healthcare accessibility, streamline communication between patients and medical professionals, and enhance overall health management, all while ensuring data privacy and security. Through this service, patients can stay informed about their health, make more proactive decisions, and access necessary care with greater ease. |
|||||
| Ransomware | Saudi Icon id25196 View details | Saudi Arabia | Services | — | |
|
Saudi Icon specializes in design and build solutions, offering a holistic approach to construction and turn-key services. The company caters to a diverse clientele, including hotels, workspaces, restaurants, gyms, and healthcare facilities across Saudi Arabia. With a focus on creativity, functionality, and quality construction, Saudi Icon aims to redefine modern living through thoughtful design and tailored services. Their extensive portfolio showcases significant projects, along with a reputation for delivering high-end fit-out solutions and innovative constructions |
|||||
| Ransomware | Leadway Assurance id24703 View details | Nigeria | Communication / Marketing | — | |
|
Leadway Assurance Company Limited is the leading insurance provider in Nigeria, offering a comprehensive range of products including life, education, auto, travel, health, and property insurance. The company caters to both individual and business clients, providing solutions such as wealth management and prompt claims processing. With a commitment to customer satisfaction, Leadway ensures financial security for customers and their assets through tailored insurance plans. Established in 1970, Leadway is recognized for its reliability and proactive service in the insurance sector. |
|||||
| Ransomware | CT Dent Ltd id24481 View details | United Kingdom | Healthcare / Pharma | — | |
|
CT Dent Ltd is an independent CBCT imaging centre based in London, UK, specializing in dental CT scanning services that are utilized by over 10,000 UK practices. The company offers a range of imaging services, including CBCT scans, OPG X-rays, and digital impressions, along with advanced technologies like dose reduction to ensure patient safety. Their target clients include dental practitioners in need of reliable and detailed imaging for treatment planning and diagnostics. Established in 2007, CT Dent has become a leading provider in the dental imaging sector |
|||||
| Ransomware | National Civil Service Commission of Colombia id23792 View details | Colombia | Public Sector | ||
|
The official portal of the Comisión Nacional del Servicio Civil (CNSC), Colombia’s National Civil Service Commission. This government body is responsible for overseeing the recruitment, selection, and management of public servants in the country. It ensures that hiring for government positions is fair, transparent, and based on merit. The site provides essential information about job openings in the public sector, application processes, and the regulations that govern public service employment in Colombia. It serves as a key resource for individuals seeking to apply for civil service positions or learn about public sector employment in Colombia |
|||||
| Ransomware | Defensoría del Pueblo de Colombia – Protection and Promotion of Human Rights id23791 View details | Colombia | Communication / Marketing | ||
|
The official online portal of the Defensoría del Pueblo de Colombia, a constitutional and autonomous institution responsible for promoting, protecting, and defending human rights across the country. It serves as a public platform where citizens can access information about their rights, file complaints, seek legal guidance, and learn about the institution’s oversight and advocacy efforts. The Defensoría operates independently from other branches of government and plays a key role in ensuring that state entities respect and uphold fundamental rights, especially for vulnerable populations |
|||||
| Ransomware | Doctor Alliance – Streamlined Document and Billing Management for Healthcare Providers id23790 View details | United States | Healthcare / Pharma | ||
|
Doctor Alliance (doctoralliance.com) is a U.S.-based healthcare technology platform that helps physicians and medical agencies manage documents, referrals, and billing in one secure online system. Headquartered in Dallas, Texas, it offers services such as electronic document signing, coordination with agencies, and billing support for programs like CPO, CCM, and TCM. The platform integrates with systems like Axxess Home Health to streamline workflow and reduce paperwork, promoting faster document turnaround and improved billing efficiency -- contact me to protect your files !! |
|||||