Skip to main content
Mallory

Kairos

Also known asKairos

Kairos is a ransomware/extortion group active on several Russian-language hacking forums that, according to the provided reporting, does not appear to be linked to other hacking groups. The group emerged around July 2024 with a dedicated data leak site (DLS), was first observed in November 2024, and continued operating into 2025 and 2026. Reporting in the provided content attributes at least 59 claimed victims between November 2024 and January 2026, at least 79 claimed victims since first observation, and 27 incidents in May 2026. Kairos operates a time-bound extortion model centered on data exfiltration and staged public disclosure. Victims are initially given seven days to respond to its demands; if no agreement is reached, Kairos publishes an initial leak post. If the dispute remains unresolved, the group says it will notify partners, competitors, and customers and ultimately publish stolen data in full. The content also states Kairos pressures victims with escalation deadlines, discourages contacting law enforcement or incident response firms, and threatens consequences including legal action, contract termination, reputational damage, stock value drops, and potential organizational closure. The provided content links Kairos to claimed victim postings on its leak site, including FriendlyCare Pharmacy in Booval, Queensland, where it allegedly posted sample data including scripts, an incident report, employment correspondence, a licence, and personal and medical information. The content also states Kairos claimed responsibility for Seagrass Boutique Hospitality Group on 12 February 2026. Known aliases in the provided content: kairos.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

2 of 15 tactics4 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0010
Exfiltration
2 techniques
T1020
Automated Exfiltration
T1041
Exfiltration Over C2 Channel
TA0040
Impact
2 techniques
T1486
Data Encrypted for Impact
T1657
Financial Theft
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping4

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.