Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareRansomware

Radiant

Radiant is a newly emergent ransomware/extortion group. The content links it to the compromise of the global nursery chain Kido, where it claimed to have stolen sensitive data on approximately 8,000 children and their families. Reported stolen data included names, home addresses, photographs, contact details, medical records, and safeguarding notes. Radiant used the data for extortion, demanding about £600,000 in Bitcoin in one report and $800,000 in another, contacting parents directly, and posting or leaking some children’s images to pressure payment. The intrusion into Kido was reported as occurring via Famly, a third-party software service used by Kido. After backlash from the cybersecurity community and criticism on the RAMP forum, Radiant said a partner had violated its rules by targeting a childcare company, claimed it removed Kido-related data, provided a security report and deletion log, and stated it would disable intrusions against organizations holding children’s information.

The group also claimed to have targeted an unnamed hospital in Minnesota, reportedly setting an Oct. 13 deadline and threatening to identify the victim if its demands were not met. Separately, Radiant was listed on a leak site as an active threat in connection with Magna Foodservice in Germany on October 12, 2025. The content explicitly describes Radiant as a ransomware gang/group and an active leak-site extortion actor. No confirmed technical malware family details, encryption behavior, or specific indicators of compromise are provided in the source content.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.