Kairos is a cyber extortion group active since late 2024 that operates a dedicated leak site and is best characterized as a data-theft extortion actor rather than a confirmed file-encrypting ransomware operation. Reporting consistently indicates that Kairos steals data, threatens publication, and uses staged disclosure and deadline pressure to coerce payment; no encryptor, locker binary, or verified decryption workflow has been confidently linked to the group. Kairos has been observed on Russian-language cybercrime forums and has run a leak-and-negotiation model in which victims are typically given a short response window before an initial leak post, followed by broader publication and pressure tactics if negotiations fail. The group has also used name-and-shame tactics and claimed numerous victims across multiple countries. Kairos has targeted organizations in government, manufacturing, education, and healthcare, with observed victims in the United States, Canada, France, New Zealand, and Australia. Public reporting links the group to a notable 2025 extortion case involving a small U.S. government entity that paid approximately $1 million after Kairos claimed to have exfiltrated more than 2 TB of data. In that case, Kairos allegedly obtained initial access through brute-forcing credentials, relied on exfiltration and publication threats rather than encryption, and provided post-payment deletion claims that were not independently verifiable. Observed tradecraft includes initial access via brute-force credential attacks, large-scale data exfiltration, extortion through leak threats, and negotiation pressure using countdowns, escalating deadlines, reputational pressure, and references to especially sensitive data. Kairos has maintained leak-site infrastructure and negotiation channels and has been associated with backend infrastructure later seized by Ukraine’s security service. Available evidence supports financial motivation centered on data-theft extortion rather than espionage or destructive objectives. No high-confidence evidence in the supplied material establishes affiliation with another major ransomware brand or confirms use of encryption in its operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
26 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack against Warwick Fabrics.
Conducting a ransomware attack against Thermalex Inc.
Conducting a ransomware attack against College O’Sullivan de Québec, an education-sector organization in Canada.
Named as the ransomware group responsible for an attack against Collège O’Sullivan de Québec.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.