Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors kairos

Description

Kairos is a data extortion group active since late 2024 that focuses solely on data theft with no encryption, primarily targeting small-to-mid-sized organizations in healthcare, manufacturing, and business services in the US, purchasing initial access from brokers and demanding Bitcoin payments. Known victims: 82 1 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Kairos is a medium-sophistication criminal threat actor specializing in data extortion through ransomware activities. Targeting small-to-mid-sized organizations in healthcare, manufacturing, and business services primarily in the US, Kairos employs initial access purchased from brokers to extort Bitcoin payments. With over 82 known victims across various sectors and international entities, Kairos poses a persistent financial threat leveraging data theft and organizational disruption.

Goals & Targeting

Kairos' primary objectives are ransomware deployment and financial gain. They target sectors with potentially valuable or recoverable data, focusing on small-to-mid-sized organizations that may lack robust security measures. Their targeting strategy likely aims to maximize profitability with minimal operational overhead by leveraging existing system access.

Enhanced Description

Kairos represents a data extortion group emerged in late 2024, focusing on the healthcare, manufacturing, and business service sectors. They primarily target small-to-mid-sized organizations in the US, though their activities extend to international entities like Paraguay. Kairos operates by purchasing initial access from brokers, indicating a reliance on pre-compromised systems for their attacks. Their modus operandi involves extorting Bitcoin payments through data theft and ransomware deployment, as evidenced by over 82 known victims across campaigns such as Gregory Jewellers and Mortensenlawoffices. While their operational timeline spans from June 2024 to July 2026, specific details on their tactics, techniques, and procedures (TTPs) remain limited, highlighting a need for further analysis.

Key Capabilities

  • Data extortion
  • Ransomware deployment
  • Bitcoin transactions for extortions
  • Purchase of initial access from brokers

Campaigns & Victims

Kairos has conducted multiple campaigns across various sectors and countries. Their victims include entities like Strata Republic, FriendlyCare Pharmacy, and Nordenta (a subsidiary of LIFCO), indicating an adaptable approach to target selection. The absence of specific linked techniques or tools suggests they may utilize generic methods, possibly involving social engineering and purchased access.

IOC Patterns

  • Spear-phishing attempts
  • Ransomware encryption patterns
  • Bitcoin wallet addresses for payments
  • C2 communications via established channels

Recommended Actions

  • Implement employee training on phishing detection
  • Enhance network security monitoring
  • Establish robust backup and recovery systems
  • Conduct regular vulnerability assessments

Suggested Tags

Ransomware
Data Extortion
Financial Crime
Healthcare Sector

Confidence Assessment

Moderate confidence in Kairos' existence, activity span, and targeting sectors. Gaps include specific TTPs, tools used, and exact methods of initial access acquisition.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

22

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Healthcare Targeting
Data Exfiltration
Data Extortion
Financial Crime
Healthcare Sector

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Jun 26, 2024
Last Seen
Jul 30, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.