Za Woo — Ransomware Profile

Za Woo (also tracked as ZaWoo or ZAWOOO) is a financially motivated double-extortion crew whose Tor data-leak site surfaced on tracker platforms in late August 2026 with an initial burst of at least 16 claimed victims across Germany, Austria, Czechia, Brazil, Canada, New Zealand and the United States, weighted toward German firms in manufacturing, hospitality, professional services, retail and technology. PCrisk analyzed the group's encryptor from VirusTotal submissions in mid-August 2026: it renames encrypted files to random strings, drops a note branding the operation as ransomware that “prioritizes reputation”, and threatens to email stolen data to a victim's customers if payment is refused, directing talks to an onionmail address and the Session messenger; the same recovery address appears in RansomLook's record of the leak site also catalogued by ransomware.live.

IntelFusions coverage (1)

Recent claimed victims

Read the full analysis on IntelFusions