Ransomware Group intelligence
ZaWoo
ActiveTrack ZaWoo with 33 published victims and 1 known leak locations in a single intelligence view.
Overview
ZaWoo is tracked by Breach House as a ransomware group with 33 published victims.
Germany is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Unknown | fyenuhkq3pfhnbpidj5jm2fl2lryxip4byhg6eozynrnlomu4szf2nyd.onion |
Top Activity Sectors (7)
Typical Attacks (12)
▼MITRE ATT&CK does not currently catalogue ZaWoo, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: ZaWoo executes malicious payloads via PowerShell to automate reconnaissance and persistence on compromised hosts.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: ZaWoo disables security tools by terminating antivirus processes and modifying system defenses to hinder recovery.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: ZaWoo encrypts and encodes victim files with custom symmetric keys to ensure data remains inaccessible.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: ZaWoo deletes Volume Shadow Copies and backup directories via vssadmin to prevent data restoration.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1564.003 Hidden Window Stealth
What they do: ZaWoo hides malicious processes and command execution behind hidden windows to evade detection.
What that means: Adversaries may use hidden windows to conceal malicious activity from the plain sight of users.
-
T1083 File and Directory Discovery Discovery
What they do: ZaWoo performs file and directory discovery to identify sensitive assets and prepare encryption targets.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1135 Network Share Discovery Discovery
What they do: ZaWoo uses network share discovery to locate victim file shares and target critical data across the network.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1614.001 System Language Discovery Discovery
What they do: ZaWoo discovers system language settings to tailor ransom notes and localization of malicious communications.
What that means: Adversaries may attempt to gather information about the system language of a victim in order to infer the geographical location of that host.
-
T1560.001 Archive via Utility Collection
What they do: ZaWoo archives stolen data using utility commands for potential exfiltration and extortion demands.
What that means: Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration.
-
T1486 Data Encrypted for Impact Impact
What they do: ZaWoo encrypts victim files using custom ransomware routines to maximize operational disruption and extortion leverage.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: ZaWoo stops critical Windows services such as backup and monitoring services to disrupt incident response.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: ZaWoo inhibits system recovery by corrupting restore points and disabling backup services before encryption.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (33)
Search, filter and paginate the victim timeline for ZaWoo. Showing 1–33 of 33.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | zenithtechnology id32289 View details | New Zealand | IT | ||
|
ZenithTechnology operates within the IT sector and is situated in New Zealand. The entity is documented within this threat-intelligence index as a ransomware victim associated with the threat actor ZaWoo. This listing type indicates a cybersecurity incident where the organization was impacted by ransomware activity linked to ZaWoo. The description adheres to neutral, authoritative reporting standards without inventing specific technical details, breach confirmations, or unverified claims regarding data handling or operational impact. The catalog entry serves to inform stakeholders of the association between ZenithTechnology and ZaWoo within the ransomware victim classification. |
|||||
| Ransomware | zenithtechnology id32289 View details | New Zealand | IT | ||
|
[Unpublished] |
|||||
| Ransomware | fessport id32290 View details | Germany | Services | ||
|
fes-sport.de is a domain operating within the Services sector based in Germany (DE), providing professional and commercial service offerings under its domain identity. The entity has been cataloged in this threat-intelligence index under the listing type ransomware victim, with the associated threat actor ZaWoo identified as the source of the attributed incident. This record serves as a factual reference point for monitoring cybersecurity events, threat actor activity, and potential impacts across the services sector in Germany. No specific incident details such as data stolen, ransom demands, or breach confirmation are included, maintaining strict neutrality per cataloging protocols. It was listed as a ransomware victim associated with ZaWoo. |
|||||
| Ransomware | fessport id32290 View details | Germany | Services | ||
|
[Unpublished] |
|||||
| Ransomware | esopartnerscpa id32291 View details | United States | Finance / Legal / Insurance | ||
|
esopartnerscpa operates within the United States across Finance, Legal, and Insurance sectors, providing specialized partnership and service offerings relevant to regulated industries. As a ransomware victim entry in the threat-intelligence index, it is associated with the ZaWoo threat actor, indicating exposure within a cybersecurity incident context. The listing type identifies esopartnerscpa specifically as a ransomware victim, contextualizing its role within broader cyber threat analysis and sector-focused intelligence monitoring. This description avoids speculation regarding data scope, breach confirmation, or operational impact, maintaining factual neutrality consistent with threat-intelligence catalog standards. |
|||||
| Ransomware | esopartnerscpa id32291 View details | United States | Finance / Legal / Insurance | ||
|
[Unpublished] |
|||||
| Ransomware | esopartnerscpa id32291 View details | China | Finance / Legal / Insurance | ||
|
[Unpublished] |
|||||
| Ransomware | vectorsoft.de id32292 View details | Germany | IT | ||
|
vectorsoft.de is an IT sector entity based in Germany, operating within the digital services domain and cataloged under threat-intelligence records as a ransomware victim. The entity's classification reflects its involvement in an incident linked to the ZaWoo threat actor, a group documented in cyber threat intelligence databases. This listing type indicates the entity was identified within the scope of ransomware activity targeting organizations in the IT sector. The description adheres to neutral, encyclopedic standards without speculating on unverified technical or operational details of the incident. vectorsoft.de remains a reference point in threat-intelligence indexing for entities affected by ZaWoo-associated ransomware operations. |
|||||
| Ransomware | vectorsoft.de id32292 View details | Germany | IT | ||
|
vectorsoft is Vectorsoft AG, a German software-development company headquartered in Heusenstamm, Hesse, near Frankfurt am Main, Germany. |
|||||
| Ransomware | winterdienst-berlin.com id32293 View details | Germany | Services | ||
|
winterdienst-berlin.com operates within the Services sector located in Germany. The domain name suggests specialized service functions, though specific operational details remain limited within public threat intelligence records. As cataloged in the threat-intelligence index, this entity is classified as a ransomware victim linked to the ZaWoo threat actor group. The association indicates exposure to ransomware activity within the German services environment. This listing serves to contextualize the entity within broader cyber threat patterns and actor attribution frameworks. |
|||||
| Ransomware | winterdienst-berlin.com id32293 View details | Germany | Services | ||
|
The company is located at Boschweg 18–20, 12057 Berlin, and lists [email protected] and +49 30 684 083-6 as contact details. According to their company website, their services include:Snow and slush removal Clearing and gritting of sidewalks, roads, parking areas and public spaces Manual and machine-assisted winter maintenance Winter-service operations for businesses, private households and municipalities GPS-supported fleet and quality controls Environmentally conscious winter-service methods.Availability around the clock during winter conditions .The company says it combines around 30 years of experience with modern technology and environmentally friendly materials. |
|||||
| Ransomware | hd-werkstaetten.de id32294 View details | Germany | Manufacturing / Engineering | ||
|
hd-werkstaetten.de operates within the German manufacturing and engineering sector, focusing on industrial production and technical solutions. The entity was formally cataloged as a ransomware victim linked to threat actor ZaWoo. Threat intelligence indexing captures such associations to enhance situational awareness for cybersecurity professionals monitoring industrial threats. This listing reflects the cybersecurity community's documentation of the incident without disclosing confirmed technical details or operational impact. Understanding these victim profiles aids in refining defense strategies for similar manufacturing organizations in Europe. |
|||||
| Ransomware | hd-werkstaetten.de id32294 View details | Germany | Manufacturing / Engineering | ||
|
hd-werkstaetten.de belongs to Heidelberger Werkstätten der Lebenshilfe Heidelberg e. V., a German social enterprise / sheltered workshop organization supporting people with disabilities through employment, vocational training, and workplace inclusion. Its main site is in Heidelberg, Baden-Württemberg, Germany. |
|||||
| Ransomware | ng-engineering.de id32295 View details | Germany | Manufacturing / Engineering | ||
|
ng-engineering.de is a German entity operating within the manufacturing and engineering sector, providing engineering-focused services and solutions aligned with industrial production and technical development needs. The domain and organization are cataloged in this threat-intelligence index under the listing type ransomware victim. The association with threat actor ZaWoo indicates that this entity was impacted by ransomware activity linked to ZaWoo's operations. No specific incident details, such as data stolen, ransom demands, or confirmed breach metrics, are included to maintain factual neutrality and avoid speculation. This listing serves to inform security professionals and stakeholders of the entity's status within the ransomware threat landscape for the German manufacturing and engineering sector. |
|||||
| Ransomware | ng-engineering.de id32295 View details | Germany | Manufacturing / Engineering | ||
|
NG Engineering Gruppe is a German engineering and technical-services group headquartered in Rödental, Bavaria. The group has been operating for more than 20 years and has locations in Germany, Poland and the Czech Republic. It provides engineering services throughout the product-development process and also offers personnel/recruitment services. |
|||||
| Ransomware | berghotel-oberhof.de id32296 View details | Germany | Hospitality / Food & Beverage / Tourism | ||
|
berghotel-oberhof.de operates within the German hospitality, food and beverage, and tourism sectors, providing lodging and related services to guests. The domain represents an organization whose infrastructure was identified within a threat-intelligence index as a ransomware victim. This listing associates the entity with ZaWoo, a threat actor noted in cyber threat reporting. No specific incident details such as data stolen, ransom demands, or breach confirmation are included per strict factual constraints. The catalog entry documents the association neutrally for threat-intelligence and security awareness purposes. |
|||||
| Ransomware | berghotel-oberhof.de id32296 View details | Germany | Hospitality / Food & Beverage / Tourism | ||
|
Konsumhotel Berghotel Oberhof is a wellness and leisure hotel in Oberhof, Thuringia, Germany, located in the Thuringian Forest. It is operated by Berghotel Oberhof GmbH, with Markus Barth as managing director. |
|||||
| Ransomware | rsk-immobilien.de id32297 View details | Germany | Construction / Real Estate | ||
|
rsk-immobilien.de operates within the German construction and real estate sector, offering services aligned with property management and related commercial activities. The entity is cataloged in this threat-intelligence index as a ransomware victim associated with ZaWoo, a threat actor identified in cybersecurity threat reporting. This listing type indicates documented exposure to ransomware activity within the organization's operational environment. Details regarding specific attack vectors, data impacts, or remediation steps remain intentionally limited to preserve factual accuracy and avoid speculation beyond verified intelligence sources. The entry serves to inform security professionals and stakeholders about real-world incidents affecting entities in this sector and geographic region. |
|||||
| Ransomware | rsk-immobilien.de id32297 View details | Germany | Construction / Real Estate | ||
|
RSK Immobilien GmbH is a German real-estate project developer and property company headquartered in Weißenfels, Saxony-Anhalt. Its core activities are the development, realization, renovation and marketing of residential and commercial properties, with a strong current focus on residential projects. |
|||||
| Ransomware | montronix.de id32298 View details | Germany | Manufacturing / Engineering | ||
|
montronix.de is a German entity operating within the manufacturing and engineering sector, providing specialized technical and industrial solutions for production, design, and operational workflows. The domain is cataloged as a ransomware victim associated with threat actor ZaWoo. This designation reflects its inclusion in threat-intelligence records documenting cyber incidents affecting organizations in this region and industry. No specific breach details, stolen data categories, record counts, ransom demands, or confirmed incident specifics are included here to maintain factual neutrality. The entry serves to index the entity alongside its threat context for security analysts and defenders monitoring ZaWoo activity across manufacturing environments. |
|||||
| Ransomware | montronix.de id32298 View details | Germany | Manufacturing / Engineering | ||
|
MONTRONIX GmbH is a German industrial technology company specializing in machine-tool monitoring, process monitoring, machine protection, and condition monitoring. The company was founded in 1990 as a spin-off of Kennametal, Inc. and focuses primarily on monitoring solutions for metal-cutting and machining operations. |
|||||
| Ransomware | kdynium.cz id32299 View details | Czechia | IT | ||
|
kydynium.cz operates within the IT sector and is situated in the Czech Republic. The entity functions as a technology provider or service organization whose infrastructure was impacted by a ransomware incident. This listing type categorizes kdynium.cz as a ransomware victim within the threat-intelligence index. The association with ZaWoo identifies the specific threat actor linked to this event in the intelligence record. The description remains factual and neutral, focusing on the entity's classification and context without elaborating on unconfirmed technical details or incident specifics. |
|||||
| Ransomware | kdynium.cz id32299 View details | Czechia | IT | ||
|
KDYNIUM a. s. is a Czech precision foundry based in Kdyně, Plzeň Region, specializing in precision castings made using the lost-wax (investment casting) process. The company says its foundry has been operating since 1954, while the current joint-stock company was incorporated in 1992. |
|||||
| Ransomware | frm.ind.br id32300 View details | Brazil | Services | ||
|
frm.ind.br is an entity operating within the Services sector located in Brazil, with offerings aligned to professional and commercial service delivery. The entity is cataloged within the threat-intelligence index as a ransomware victim, specifically associated with the ZaWoo threat actor. This listing reflects the entity's documented exposure within cybersecurity threat datasets, providing context for threat researchers and defenders monitoring ransomware campaigns targeting the Services sector in the Brazilian market. The entry serves as a reference point for understanding attack patterns and entity vulnerability without disclosing unverified incident details. frm.ind.br was listed as a ransomware victim associated with ZaWoo. |
|||||
| Ransomware | frm.ind.br id32300 View details | Brazil | Services | ||
|
FRM - Fábrica de Rolamentos e Mancais Ltda is a Brazilian industrial manufacturer specializing in bearings, bearing housings, and industrial movement solutions. The company is based in Curitiba, Paraná, Brazil and has been operating since 1980. |
|||||
| Ransomware | acqbuilt.com id32301 View details | Canada | IT | ||
|
acqbuilt.com operates within the IT sector and is identified as a ransomware victim within the threat-intelligence index. The entity is geographically associated with Canada and represents a target profile relevant to cyber threat analysis. Its inclusion reflects documented intelligence linking this organization to the ZaWoo threat actor group, providing context for security professionals monitoring ransomware activity in the technology sector. This listing serves as a factual reference point for catalog users assessing affected entities and associated threat actors without disclosing unverified incident details. |
|||||
| Ransomware | acqbuilt.com id32301 View details | Canada | IT | ||
|
company based in Edmonton, Alberta, Canada. It specializes in using factory-based construction methods to build residential homes faster, with more precision, and with reduced waste compared with traditional on-site building. |
|||||
| Ransomware | BOTEC-CZ id32302 View details | Germany | Manufacturing / Engineering | ||
|
BOTEC-CZ is a company operating within the manufacturing and engineering sector, based in Germany. The entity provides specialized industrial services and technical solutions relevant to production and engineering workflows across its operational region. It is cataloged in this threat-intelligence index as a ransomware victim, with the associated threat actor and source identified as ZaWoo. This listing reflects the entity's status within the ransomware incident database without disclosing unverified operational details or confirming specific breach specifics. The entry serves threat analysts assessing cyber risks across industrial sectors and geographic regions. |
|||||
| Ransomware | BOTEC-CZ id32302 View details | Germany | Manufacturing / Engineering | ||
|
boTec helps companies in process and production industries improve efficiency, manage data, and optimize business operations using software solutions, consulting, and integration services. |
|||||
| Ransomware | n-tree.com id32303 View details | Austria | IT | ||
|
n-tree.com operates within the IT sector and is associated with the threat actor ZaWoo in this ransomware victim listing. The entity represents an organization impacted by cyber activity attributed to ZaWoo, with operational context tied to Austria. This catalog entry provides neutral documentation of the relationship between n-tree.com and ZaWoo within the threat-intelligence index framework. No specific incident details, breach confirmations, data impacts, or financial claims are included per strict factual guidelines. The listing type identifies n-tree.com as a ransomware victim connected to ZaWoo for analytical and defensive reference purposes. |
|||||
| Ransomware | n-tree.com id32303 View details | Austria | IT | ||
|
They develop software and hardware solutions mainly for visitor management and ticketing systems used by: swimming pools and wellness centers, museums and exhibitions, leisure parks, climbing gyms and fitness facilities, mountain railways and ski lifts, industrial visitor systems. Their main locations include: Bregenz, Austria (head office), Delitzsch, Germany, Heimberg, Switzerland, Riazzino, Switzerland/Italian region. |
|||||
| Ransomware | hoerburger id32304 View details | Germany | Retail / E-commerce | ||
|
hoerburger.de operates within the German retail and e-commerce sector, providing online commerce services and related business functions. The entity was formally listed within the threat-intelligence index under the designation ransomware victim, associated with threat actor ZaWoo. This classification reflects the cybersecurity event documented in the index, without disclosing specific technical findings or confirmed breach details. The listing underscores vulnerabilities within digital retail infrastructure and serves as a reference point for threat actors and defenders monitoring ZaWoo activity in European commerce environments. Authorities and industry stakeholders reference such entries to understand evolving risks across e-commerce sectors. |
|||||
| Ransomware | hoerburger id32304 View details | Germany | Retail / E-commerce | ||
|
[Unpublished] |
|||||