Kairos is a cyber extortion group active since late 2024 that operates a dedicated leak site and appears to specialize in data-theft extortion rather than confirmed file-encrypting ransomware. Reporting consistently describes the group as exfiltration-first: stealing victim data, threatening publication, imposing short deadlines, and using staged leak pressure to coerce payment. No encryptor, locker binary, or verified ransomware payload has been confidently linked to Kairos in the available evidence, so it is best characterized as a data-theft extortion actor rather than a confirmed traditional ransomware operator. Kairos has targeted organizations across multiple sectors and countries, including U.S. government entities, manufacturing companies, educational institutions, healthcare-related organizations, and local government bodies. Observed victims include entities in the United States, Canada, France, New Zealand, and Australia. Public reporting also places Kairos among active leak-site extortion actors during 2025 and 2026, with dozens of claimed victims. The group’s known tradecraft includes initial access via brute-force attacks against credentials, followed by data exfiltration and extortion. Kairos uses negotiation portals and leak-site postings to pressure victims, typically giving a limited response window before publishing an initial leak post and escalating toward broader disclosure of stolen data. Reported pressure tactics include countdown timers, deadline escalation, reputational pressure, and threats to notify third parties such as customers, partners, or competitors. In at least one documented case involving a U.S. government victim, Kairos claimed to have stolen more than 2 TB of data, negotiated from an initial multimillion-dollar demand down to a seven-figure payment, and provided purported proof of deletion that was not independently verifiable. Kairos has been observed on Russian-language cybercrime forums and does not appear to be firmly linked to another named intrusion set. Infrastructure associated with the operation was at one point traced to a backend hosted in Ukraine and was later reported seized by the Cyber Department of the Security Service of Ukraine, but this does not by itself establish Ukrainian origin. Overall, Kairos is notable for pure extortion operations centered on data theft, leak-site coercion, and aggressive negotiation rather than demonstrated encryption capability.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
26 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack against Hightech Signs.
Conducting a ransomware attack against Warwick Fabrics.
Conducting a ransomware attack against Thermalex Inc.
Conducting a ransomware attack against College O’Sullivan de Québec, an education-sector organization in Canada.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.