Ransomware Intelligence

kairos

Ransomware group profile

69Victims
RussiaSource country
83Impact score
Also Known As
Kairos Extortion Group

Description

Kairos is a financially motivated cyber extortion group that emerged in November 2024, primarily focusing on data theft and extortion rather than traditional ransomware tactics. Their strategy leverages the threat of data exposure to pressure victims into compliance while employing psychological manipulation tactics to maximize ransom payments.

Key insights

  • Kairos employs initial access brokers and exploits vulnerable remote services to gain access to victim networks.
  • The group exfiltrates sensitive data and threatens public disclosure to extract ransom payments from victims.
  • RClone, a legitimate file transfer utility, is a key tool utilized for data staging and exfiltration.
  • Kairos meticulously clears Windows Event Logs to evade detection during their operations.
  • They tailor ransom demands based on the financial capacity of the target and offer discounts for immediate payment.

Threat Level & Status Breakdown

For kairos · Based on incidents in selected period

3.3threat level
Aggressiveness6/ 10
Lethality0/ 10
Criticality4.1/ 10

Status Breakdown

Claimed69.6%48
First seenJun 2025
Last seenMay 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 2, 2026

Recent activity

Monthly attack count for kairos in the selected period

69Total attacks
10peak in Jun
6.3avg / month
↓ 5 vs first month
JunJulAugSepOctNovDecFebMarAprMay036912

Intelligence

IOCs, YARA/Sigma rules, and related families for kairos

  1. d520d06d78afcad2e03842cb8db4622d18b92739e89dfb8dadf5743f30dcd903
View full IOC feed500 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for kairos

CVE-2026-41940
CVE-2026-3854
CVE-2026-31431
Other

T1486

T1486

T1490

T1490

T1070.001

T1070.001

T1562.001

T1562.001

T1078

T1078

T1047

T1047

T1021.001

T1021.001

T1059

T1059

T1583

T1583

T1550

T1550

T1040

T1040

T1027

T1027

Victims(69)

CompanyDomainCountryIndustryStatusDiscovered
Commune De CamiersFR FranceGovernment & Defense
Unknown
5 days ago
McCarthy IncUS United StatesOther
Unknown
19 days ago
ArwiniDE GermanyHealthcare
Unknown
23 days ago
Ayuntamiento de ValdemoroES SpainGovernment & Defense
Unknown
23 days ago
Houk Air Conditioninghoukac.comUS United StatesProfessional Services
Unknown
28 days ago
Gregory JewellersAU AustraliaRetail & E-Commerce
Claimed
about 1 month ago
Nordenta (a daughter company of LIFCO)DK DenmarkHealthcare
Claimed
about 1 month ago
Strata RepublicAU AustraliaProfessional Services
Claimed
about 2 months ago
FriendlyCare PharmacyAU AustraliaHealthcare
Claimed
about 2 months ago
Pullen MovingUS United StatesTransportation
Claimed
about 2 months ago
Colonial Presbyterian ChurchUS United StatesRetail & E-Commerce
Claimed
about 2 months ago
South Florida Injury CentersUS United StatesHealthcare
Claimed
about 2 months ago
Resch Maschinenbauresch-maschinenbau.deDE GermanyManufacturing
Unknown
2 months ago
Folet & Rivoirefrc-avocats.frFR FranceProfessional Services
Unknown
3 months ago
Institute of Social Security - Paraguayips.gov.pyPY ParaguayGovernment & Defense
Unknown
3 months ago
Katz Kantor Stonestreet & Bucknerkatzkantor.comUS United StatesProfessional Services
Unknown
3 months ago
Rockwood Retirement Communitiesrockwoodretirement.orgUS United StatesRetail & E-Commerce
Unknown
3 months ago
The Marena Groupmarena.comUS United StatesHealthcare
Unknown
4 months ago
Seagrass Boutique Hospitality Groupseagrassbhg.comAU AustraliaHospitality
Unknown
4 months ago
Robbins Parking Service Ltdrobbinsparking.comCA CanadaTransportation
Unknown
4 months ago

Page 1 of 4