Kazu is a cybercriminal extortion group that emerged in early-to-mid 2025 and is primarily associated with data-theft extortion rather than confirmed ransomware encryption operations. Reporting consistently places the group among newer, smaller extortion actors whose activity accelerated during 2025, with victim listings spanning government, military, and healthcare organizations. Kazu has shown a notable concentration on public-sector and healthcare-related targets, including telemedicine platforms, patient portals, and healthcare service providers, and has also been linked to attacks against organizations in Latin America, the Middle East, Southeast Asia, Europe, Oceania, and North America. Kazu’s operations center on stealing sensitive data and coercing victims with threats of public release or sale. The group has used leak-site and Telegram-based publicity, ransom deadlines, and repeated extortion demands tied to allegedly exfiltrated datasets. Multiple incidents attributed to Kazu involved healthcare data, including patient records, clinical documents, billing information, and other protected health information. Victims publicly associated with Kazu include healthcare platforms in Argentina, a patient portal in New Zealand, an Italian telemedicine provider, and Doctor Alliance in the United States. Broader reporting also indicates earlier targeting of government and public-sector entities, with healthcare becoming an increasingly prominent focus. Available reporting suggests Kazu often targets internet-facing web portals and web-enabled services and may exploit unpatched or older vulnerabilities to obtain access and exfiltrate data directly from exposed applications. In at least one reported case, the actor claimed reuse of a previously exploited weakness to conduct a second intrusion after remediation statements by the victim. Analysts have also assessed that Kazu’s tradecraft is more consistent with opportunistic web-application compromise and data theft than with mature enterprise-wide ransomware deployment. There is no solid evidence in the supplied material that Kazu is a rebrand, splinter, or affiliate of another well-known ransomware group. Known aliases are limited to Kazu. The actor’s dominant behavior is financially motivated extortion through theft and threatened disclosure of sensitive information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Smaller ransomware and extortion group that emerged in mid-2025. Initially targeted government and public-sector victims, then showed a growing focus on healthcare organizations, including an Italian telemedicine provider and additional healthcare victims in Latin America.
Extortion activity targeting a healthcare/health-tech platform, with claims of stealing 3,197,677 user records and demanding a $150,000 ransom while threatening to sell the data publicly if unpaid.
Conducting extortion against healthcare/telemedicine platforms by claiming theft of large datasets and demanding ransom under a sell-or-leak threat model.
Ransomware/extortion operation against a healthcare patient portal, involving large-scale medical-record exfiltration and ransom demand with threat of public release.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.