Kairos is a cyber extortion actor active since late 2024 that is primarily associated with data-theft and leak-based coercion rather than confirmed file encryption. The group operates a dedicated leak site and has been observed using staged disclosure, short response deadlines, and public shaming to pressure victims into paying to prevent publication of stolen data. Reporting consistently characterizes Kairos as a data-only extortion operation, and no ransomware encryptor, locker binary, or verified decryption capability has been confidently linked to the group. Kairos has targeted organizations in multiple sectors and regions, including government and public-sector entities, healthcare-related organizations, and commercial victims. Public reporting links the group to extortion against a small U.S. county government in 2025, where the actor allegedly stole more than 2 TB of data and negotiated a seven-figure payment without demonstrated encryption. Victimology observed on leak-site tracking also indicates broader international activity, including incidents affecting organizations in Europe and Australia. The group’s known tradecraft centers on credential-based intrusion and data exfiltration followed by extortion. In at least one well-documented case, Kairos claimed initial access via brute-force attacks against credentials. Its coercion model relies on countdowns, escalating deadlines, high-anchor ransom demands followed by concessions, and selective references to especially sensitive stolen material to increase pressure. Kairos has also been described as threatening wider notification of partners, customers, or other third parties if negotiations fail, reflecting a broader extortion-first model rather than operational disruption through encryption. Kairos is reported to be active on Russian-language cybercrime forums but has not been conclusively tied to a larger known cluster or major parent operation. Some reporting states the group emerged around July 2024, while other tracking places first observation in November 2024; the available evidence supports activity beginning in the second half of 2024. Leak-site monitoring and industry reporting indicate the group claimed dozens of victims through 2025 and into 2026, with counts varying by observation date. Infrastructure associated with the operation was later reported seized by Ukraine’s Security Service cyber authorities. Aliases are limited, with Kairos being the primary and most widely used name. Based on currently available evidence, Kairos is best understood as an extortion-focused cybercriminal actor specializing in exfiltration-and-leak pressure tactics rather than a confirmed traditional ransomware group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
26 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Data-theft extortion operations against a US government entity, using stolen-data exposure threats rather than confirmed ransomware encryption. The group allegedly stole more than 2 TB of data, negotiated payment down from $3 million to $1 million, and claimed to provide proof of deletion after payment.
Data-only extortion operations against a U.S. government entity, involving brute-force initial access, exfiltration of more than 2 TB of data, leak-site pressure, and ransom negotiation culminating in a 1 million USD Bitcoin payment.
Cyber extortion group that allegedly breached a small Ohio county in May 2025, stole over 2 TB of data via a brute-force attack, and extorted the victim into paying $1 million in Bitcoin to avoid public release of the stolen data. The incident reportedly involved data theft and extortion rather than file encryption.
Conducting data-theft and extortion operations against a U.S. government entity, exfiltrating over 1.6 million files and demanding payment not to publish the stolen data rather than deploying file encryption.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.