One of the companies on the list clears snow from Berlin pavements. Another is a sheltered workshop in Heidelberg that employs people with disabilities. Both appeared on 30 August on the data leak site of Za Woo, an extortion crew that had never named a victim before and then named 16 of them in a single day.
Ten of the 16 are German. That is not how these lists usually look.
Across every leak site IntelFusions tracks, German organizations accounted for 5.2 percent of extortion claims over the last 30 days, 60 out of 1,146. Za Woo's opening batch is 62 percent German. The rest is scattered thin, one victim each in Austria, Czechia, Brazil, Canada, New Zealand and the United States. The names are small and mid-sized firms mostly invisible outside their own market: a machine-tool monitoring specialist in Bavaria, a software house near Frankfurt, a wellness hotel in the Thuringian Forest, a precision foundry in Czechia and a modular home builder in Edmonton.
One new brand, most of Germany's bad week
German organizations have taken 22 leak site claims in the past seven days, against a weekly average of about 12 over the preceding 90 days. Za Woo accounts for 10 of those by itself, which is most of the difference. Every other crew working German targets this week posted in low single figures: Storm three, Akira two, Qilin two, and one apiece from Aurora, Rhysida, MetaEncryptor, Krybit and Coinbase Cartel. Germany is a standing target for extortion crews, and we covered a comparable pileup in July when SafePay named a German airport operator and a charity. What is different here is that one unknown brand supplied the whole spike on its first day of operation. Our Za Woo tracking page and the Germany country profile carry the running figures.
The encryptor turned up two weeks before the victims did
The malware was already on the record. On 12 August, Tomas Meskauskas at PCrisk published an analysis of the ZAWOOO encryptor taken from a public malware sample, well before any leak site went live. It renames files completely, replacing both the name and the extension with random strings, so in the example PCrisk published the file 1.jpg became 5BE7D191BE162F03.NnaOfnYs. It drops a note called How To Restore Your Files.txt that describes the operation as "a ransomware that prioritizes reputation" and threatens, if the victim refuses to pay, to consider sending their files, chat history and mailbox contents to all of their customers by email. Negotiation is pushed to zawooorecover[at]onionmail[.]org and to the Session messenger.
A working encryptor circulating for two weeks before the first public claim is the ordinary shape of a crew that has been operating quietly and has now decided to apply pressure in public.
What a leak site post is not
These are claims the gang makes about itself, on its own infrastructure, and none of the 16 organizations has publicly confirmed an intrusion. A new brand has every incentive to look busier than it is, and a debut batch is the moment to be most careful with it. One check does come back clean: none of the 16 names appears anywhere else in our incident data under a different crew, so this is not a recycled list lifted from somebody else's leak site. That rules out one kind of padding. It does not make the claims true.
No patch to name, so watch the artifacts instead
Nobody has published how Za Woo gets in, so there is no vulnerability to fix here and anyone who tells you otherwise is guessing. The useful items are the ones the analysis actually supports. Alert on the creation of a file named How To Restore Your Files.txt across file shares, treat mass renaming of documents to random extensions as an active-encryption signal, and confirm that backups are held offline and have been restored from at least once rather than merely scheduled. German organizations that find the note should contact CERT-Bund. Any organization named on the list should work on the assumption that the data theft claim is real until it can show otherwise, because for a crew that markets itself on reputation, the leak and not the encryption is the leverage.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.