Overview
Platforms:
—
Variants:
Kairos V2
Extensions:
—
ATT&CK software:
—
Initial access:
Valid Accounts
Top countries:
US · AU · GB · CA · FR
Observed sectors:
Professional Services · Healthcare · Education · Government & Defense · Retail & E-Commerce
Tracked victims:
88
Victims
Leisure Coast Kitchens
CLAIMED
Retail & E-Commerce organization in Australia.
Ville de Libercourt
CLAIMED
Government organization in France.
Ayuntamiento de Velilla de San Antonio
CLAIMED
Government organization in Spain.
Hightech Signs
CLAIMED
Manufacturing organization in United States.
Warwick Fabrics
CLAIMED
Manufacturing organization in New Zealand.
Show more victims (11)
Thermalex Inc
CLAIMED
Manufacturing organization in United States.
LR Reed
CLAIMED
Professional Services organization in Australia.
College O'Sullivan de Québec
CLAIMED
Education organization in Canada.
Mortensen Law Offices
CLAIMED
Professional Services organization in United States.
Commune de Camiers
CLAIMED
Government organization in France.
McCarthy Inc
CLAIMED
Manufacturing organization in United States.
Arwini
CLAIMED
Organization in Germany.
Gregory Jewellers
CLAIMED
Retail & E-Commerce organization in Australia.
Nordenta
CLAIMED
Healthcare organization in Denmark.
Strata Republic
CLAIMED
Professional Services organization in Australia.
FriendlyCare Pharmacy
CLAIMED
Healthcare organization in Australia.
Operational Activity
Recent Observations
Initial Access via Exposed Remote Services
The threat actor gains initial access to victim networks by exploiting externally exposed Remote Desktop Gateway services, frequently leveraging weak or default credentials susceptible to password spraying attacks in environments lacking multi-factor authentication.
Post-Compromise Discovery and Credential Access
Following infiltration, the actor performs internal environment exploration and harvests credentials. Tools are deployed to facilitate privilege escalation and internal reconnaissance, with observed attempts to utilize PowerShell, SMB, and Remote Desktop for lateral movement.
Extortion-Only Operation Model
Kairos operates primarily as a data-extortion group that prioritizes exfiltration over file-encryption. The actor threatens public exposure of sensitive data on a dedicated leak site to coerce payment. Reported incidents often involve the theft of large volumes of data (e.g., 2 TB) without confirmed deployment of encryption lockers.
Coercive Negotiation Tactics
The group utilizes psychological manipulation, including time-bound escalation, fixed negotiation windows, and threats to increase disclosure scope if victims contact law enforcement or incident response firms. Negotiations often involve multi-million dollar demands that may be settled for lower amounts.
TTPs
ATT&CK coverage:
2 techniques
T1078
Valid Accounts
PROBABLEThe group leverages stolen or compromised valid credentials to gain unauthorized access, often acquiring them through initial access brokers.
T1190
Exploit Public-Facing Application
POSSIBLEThe group has been associated with attempts to exploit vulnerabilities in exposed internet-facing services.
CVEs
No CVE associations available.
Infrastructure
Data Leak Site (DLS)
Infrastructure associated with the Kairos leak site was later observed displaying a seizure notice attributed to Ukraine's Security Service Cyber Department, and the leak site was reported offline.
Attribution
Relationships
Qilin
PROBABLE
Suspected overlap
Blockchain analysis indicates shared cash-out points and addresses used by Kairos and Qilin for laundering victim funds, suggesting a possible shared affiliate or common infrastructure usage.
Lynx
PROBABLE
Suspected overlap
Blockchain analysis indicates shared cash-out points and addresses used by Kairos and Lynx, suggesting a possible shared affiliate or common infrastructure usage.
SafePay
PROBABLE
Suspected overlap
Blockchain analysis indicates shared cash-out points and addresses used by Kairos and SafePay, suggesting a possible shared affiliate or common infrastructure usage.
INC Ransom
PROBABLE
Suspected overlap
Blockchain analysis indicates shared cash-out points and addresses used by Kairos and INC Ransom, suggesting a possible shared affiliate or common infrastructure usage.
Affiliates
No affiliate information available.
Timeline
2025-06-13
Extortion Payment
A U.S. government entity made an approximately $1 million payment to Kairos following a data-extortion negotiation. Ransom-ISAC documented the payment using leaked negotiation records and observable blockchain activity.
2025-05-19
U.S. Government Entity Incident
A U.S. government entity was reportedly targeted by Kairos in a data-extortion incident. Public reporting has pointed to Union County, Ohio, but that identification has not been publicly confirmed.
2024-11-13
Data-Leak Site Materialization
Cyjax observed the emergence of Kairos's Tor-hosted data-leak site on or around 13 November 2024.
Sources
Kairos (Threat Actor)
Malpedia
Show more sources (16)
U.S. Government Agency Paid $1M to Data Extortion Group Kairos
Security Affairs
Ransomware & Extortion Activity
Analyst1
U.S. Government Agency Paid $1M to Data Extortion Group Kairos
Security Affairs