Overview

Platforms: —
Variants: Kairos V2
Extensions: —
ATT&CK software: —
Initial access: Valid Accounts
Top countries: US · AU · GB · CA · FR
Observed sectors: Professional Services · Healthcare · Education · Government & Defense · Retail & E-Commerce
Tracked victims: 88

Victims

Leisure Coast Kitchens CLAIMED
September 16, 2026 Australia Retail & E-Commerce 4 tracker sources
Retail & E-Commerce organization in Australia.
Ville de Libercourt CLAIMED
September 2, 2026 France Government 3 tracker sources
Government organization in France.
Ayuntamiento de Velilla de San Antonio CLAIMED
August 20, 2026 Spain Government 3 tracker sources
Government organization in Spain.
Hightech Signs CLAIMED
August 12, 2026 United States Manufacturing 3 tracker sources
Manufacturing organization in United States.
Warwick Fabrics CLAIMED
July 30, 2026 New Zealand Manufacturing 3 tracker sources
Manufacturing organization in New Zealand.
Show more victims (11)
Thermalex Inc CLAIMED
July 25, 2026 United States Manufacturing 3 tracker sources
Manufacturing organization in United States.
LR Reed CLAIMED
July 22, 2026 Australia Professional Services 3 tracker sources
Professional Services organization in Australia.
College O'Sullivan de Québec CLAIMED
July 20, 2026 Canada Education 2 tracker sources
Education organization in Canada.
Mortensen Law Offices CLAIMED
June 1, 2026 United States Professional Services
Professional Services organization in United States.
Commune de Camiers CLAIMED
May 29, 2026 France Government 3 tracker sources
Government organization in France.
McCarthy Inc CLAIMED
May 15, 2026 United States Manufacturing 3 tracker sources
Manufacturing organization in United States.
Arwini CLAIMED
May 11, 2026 Germany 3 tracker sources
Organization in Germany.
Gregory Jewellers CLAIMED
April 22, 2026 Australia Retail & E-Commerce 3 tracker sources
Retail & E-Commerce organization in Australia.
Nordenta CLAIMED
April 20, 2026 Denmark Healthcare
Healthcare organization in Denmark.
Strata Republic CLAIMED
April 17, 2026 Australia Professional Services 3 tracker sources
Professional Services organization in Australia.
FriendlyCare Pharmacy CLAIMED
April 15, 2026 Australia Healthcare 3 tracker sources
Healthcare organization in Australia.

Operational Activity

Recent Observations

Initial Access via Exposed Remote Services
The threat actor gains initial access to victim networks by exploiting externally exposed Remote Desktop Gateway services, frequently leveraging weak or default credentials susceptible to password spraying attacks in environments lacking multi-factor authentication.
Post-Compromise Discovery and Credential Access
Following infiltration, the actor performs internal environment exploration and harvests credentials. Tools are deployed to facilitate privilege escalation and internal reconnaissance, with observed attempts to utilize PowerShell, SMB, and Remote Desktop for lateral movement.
Extortion-Only Operation Model
Kairos operates primarily as a data-extortion group that prioritizes exfiltration over file-encryption. The actor threatens public exposure of sensitive data on a dedicated leak site to coerce payment. Reported incidents often involve the theft of large volumes of data (e.g., 2 TB) without confirmed deployment of encryption lockers.
Coercive Negotiation Tactics
The group utilizes psychological manipulation, including time-bound escalation, fixed negotiation windows, and threats to increase disclosure scope if victims contact law enforcement or incident response firms. Negotiations often involve multi-million dollar demands that may be settled for lower amounts.

TTPs

ATT&CK coverage: 2 techniques
T1078 Valid Accounts
PROBABLE
The group leverages stolen or compromised valid credentials to gain unauthorized access, often acquiring them through initial access brokers.
T1190 Exploit Public-Facing Application
POSSIBLE
The group has been associated with attempts to exploit vulnerabilities in exposed internet-facing services.

CVEs

No CVE associations available.

Infrastructure

Data Leak Site (DLS)
Infrastructure associated with the Kairos leak site was later observed displaying a seizure notice attributed to Ukraine's Security Service Cyber Department, and the leak site was reported offline.

Attribution

Relationships

Qilin PROBABLE
Suspected overlap
Blockchain analysis indicates shared cash-out points and addresses used by Kairos and Qilin for laundering victim funds, suggesting a possible shared affiliate or common infrastructure usage.
Lynx PROBABLE
Suspected overlap
Blockchain analysis indicates shared cash-out points and addresses used by Kairos and Lynx, suggesting a possible shared affiliate or common infrastructure usage.
SafePay PROBABLE
Suspected overlap
Blockchain analysis indicates shared cash-out points and addresses used by Kairos and SafePay, suggesting a possible shared affiliate or common infrastructure usage.
INC Ransom PROBABLE
Suspected overlap
Blockchain analysis indicates shared cash-out points and addresses used by Kairos and INC Ransom, suggesting a possible shared affiliate or common infrastructure usage.

Affiliates

No affiliate information available.

Timeline

2025-06-13
Extortion Payment
A U.S. government entity made an approximately $1 million payment to Kairos following a data-extortion negotiation. Ransom-ISAC documented the payment using leaked negotiation records and observable blockchain activity.
2025-05-19
U.S. Government Entity Incident
A U.S. government entity was reportedly targeted by Kairos in a data-extortion incident. Public reporting has pointed to Union County, Ohio, but that identification has not been publicly confirmed.
2024-11-13
Data-Leak Site Materialization
Cyjax observed the emergence of Kairos's Tor-hosted data-leak site on or around 13 November 2024.

Sources