Kairos is a financially motivated cyber-extortion group, first observed in late 2024, that conducts data-theft-only extortion rather than confirmed file-encrypting ransomware operations. No encryptor, locker binary, or verified encryption capability has been confidently linked to the group. Kairos steals victim data, lists victims on a leak site, and uses threatened publication, deadlines, countdowns, high initial demands, and negotiation pressure to coerce payment. The group has claimed brute-force attacks against credentials as an initial-access method. In a documented 2025 extortion case against an unnamed U.S. local-government entity, Kairos claimed to have exfiltrated more than 2 TB of data comprising approximately 1.6 million files. It initially demanded $3 million and ultimately received a $1 million cryptocurrency payment. Its purported evidence that it had deleted the stolen data was not independently or cryptographically verifiable. Kairos has also been linked to reported victim claims involving public-sector organizations, manufacturers, transportation firms, retail businesses, and an educational institution in the United States, Australia, Canada, France, Spain, and New Zealand. The group’s leak-site infrastructure was subsequently taken offline following a reported Ukrainian security-service seizure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
26 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Extortion group using deadline-driven escalation and defined negotiation procedures to increase pressure on victims.
Conducted a ransomware attack against Krapf Group, a U.S.-based transportation business.
Conducted a ransomware attack against Australian kitchen, laundry, and bathroom design and installation business Leisure Coast Kitchens.
Conducted a reported ransomware attack against Ville de Libercourt, a local-government organization in France.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.