Kairos is a data extortion group active since late 2024 that focuses solely on data theft with no encryption, primarily targeting small-to-mid-sized organizations in healthcare, manufacturing, and business services in the US, purchasing initial access from brokers and demanding Bitcoin payments. Known victims: 82 1 ransom note(s) on file
Objectives
Executive Summary
Kairos is a medium-sophistication criminal threat actor specializing in data extortion through ransomware activities. Targeting small-to-mid-sized organizations in healthcare, manufacturing, and business services primarily in the US, Kairos employs initial access purchased from brokers to extort Bitcoin payments. With over 82 known victims across various sectors and international entities, Kairos poses a persistent financial threat leveraging data theft and organizational disruption.
Goals & Targeting
Kairos' primary objectives are ransomware deployment and financial gain. They target sectors with potentially valuable or recoverable data, focusing on small-to-mid-sized organizations that may lack robust security measures. Their targeting strategy likely aims to maximize profitability with minimal operational overhead by leveraging existing system access.
Enhanced Description
Kairos represents a data extortion group emerged in late 2024, focusing on the healthcare, manufacturing, and business service sectors. They primarily target small-to-mid-sized organizations in the US, though their activities extend to international entities like Paraguay. Kairos operates by purchasing initial access from brokers, indicating a reliance on pre-compromised systems for their attacks. Their modus operandi involves extorting Bitcoin payments through data theft and ransomware deployment, as evidenced by over 82 known victims across campaigns such as Gregory Jewellers and Mortensenlawoffices. While their operational timeline spans from June 2024 to July 2026, specific details on their tactics, techniques, and procedures (TTPs) remain limited, highlighting a need for further analysis.
Key Capabilities
Campaigns & Victims
Kairos has conducted multiple campaigns across various sectors and countries. Their victims include entities like Strata Republic, FriendlyCare Pharmacy, and Nordenta (a subsidiary of LIFCO), indicating an adaptable approach to target selection. The absence of specific linked techniques or tools suggests they may utilize generic methods, possibly involving social engineering and purchased access.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in Kairos' existence, activity span, and targeting sectors. Gaps include specific TTPs, tools used, and exact methods of initial access acquisition.
No techniques linked yet.
No tools linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
22
Campaigns
0
IOCs
0
Observed Data
0
Tactics