Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors radiant

Description

Radiant is a financially motivated ransomware group that emerged in September 2025, conducting double- and single-extortion attacks without affiliates, drawing widespread condemnation after attacking UK childcare provider Kido International and publishing photographs, names, and home addresses of over 8,000 children. Known victims: 8

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Radiant is a financially motivated ransomware group that emerged in September 2025. Known for conducting double- and single-extortion attacks, Radiant gained notoriety after attacking the UK childcare provider Kido International, exposing sensitive information of over 8,000 children. The group operates without known affiliates and has demonstrated a clear focus on maximizing financial gain through ransomware campaigns.

Goals & Targeting

Radiant's primary motivation is financial gain, achieved through the deployment of ransomware and double-extortion schemes. The group targets sectors where data sensitivity and potential for victim shaming can maximize pressure to pay ransoms. Their selection of Kido International as a target highlights an apparent preference for industries with significant public exposure and high stakes—such as healthcare or education—and where data breaches could cause widespread harm. Radiant's targeting appears geographically unrestricted, but their attacks have occurred predominantly in regions with weaker cybersecurity defenses, particularly in Europe and North America.

Enhanced Description

Radiant is a recently emerged ransomware group with a primary focus on generating financial profit through extortion attacks. The group first gained prominence in September 2025, following an attack on the UK-based Kido International, a childcare provider. This incident involved not only the deployment of ransomware but also the exfiltration and publication of sensitive data, including photographs, names, and home addresses of children under their care. Radiant's attacks demonstrate a clear preference for double extortion tactics, where victims are pressured to pay twice: once to regain access to encrypted systems and again to prevent the disclosure of stolen data. The group has not been linked to any known affiliates, suggesting an independent operational model. WhileRadiant's geographic targeting appears broad, their attacks have caused significant impact due to the sensitive nature of their victim selection. The group's emergence coincides with a broader trend of ransomware-as-a-service (RaaS) models, though Radiant operates as a standalone entity rather than renting out their services to others.

Key Capabilities

  • Ransomware deployment with double-extortion tactics
  • Data exfiltration and victim shaming techniques
  • Lateral movement within networks to identify high-value data
  • Use of custom ransomware or known ransomware families
  • Staging infrastructure for command-and-control (C2) communication

MITRE ATT&CK Tactics

Data Exfiltration
Defense Evasion
Discovery
Lateral Movement
Exfiltration

ATT&CK Techniques

T1059.003
T1055
T1566.001
T1078
T1040

Software / Tooling

Ransomware (likely custom or unspecified)
Cobalt Strike (for some attacks)
Qbot (as a linked TTP)

Campaigns & Victims

Radiant's campaigns demonstrate a focus on high-impact targets with the potential for significant reputational damage. The group's operational timeline is still emerging, but their targeting of healthcare and education sectors suggests an intent to maximize emotional and financial pressure on victims. Radiant appears to favor persistent access and lateral movement within networks to identify and exfiltrate sensitive data before initiating encryption and demanding ransoms. Notable past operations include the Kido International attack, which highlighted their preference for victim shaming alongside traditional ransom demands.

IOC Patterns

  • Spear-phishing emails with malicious links or attachments
  • Ransomware payloads delivered via C2 servers
  • Exfiltration of sensitive data before encryption
  • Use of established malware frameworks like Qbot
  • Encryption of files with custom or known ransomware

Recommended Actions

  • Implement robust backup and recovery solutions to minimize the impact of ransomware attacks.
  • Conduct regular employee training on identifying phishing attempts and suspicious emails.
  • Monitor for unusual network activity, particularly lateral movement and data exfiltration patterns.
  • Apply endpoint detection and response (EDR) solutions to identify and block known ransomware behaviors.
  • Ensure strong access controls and encryption practices for sensitive data repositories.

Suggested Tags

ransomware
double-extortion
financial-motivation
healthcare-sector
education-sector

Confidence Assessment

The available data on Radiant is still emerging, with limited details about their long-term goals or operational structure. While the group's involvement in high-profile attacks like the Kido International incident provides significant context, gaps exist in understanding their technological capabilities beyond known TTPs and linked intelligence. The absence of a definitive attack pattern or specific tools attributed to Radiant leaves some uncertainty in their full operational scope.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
ransomware
double-extortion
financial-motivation
healthcare-sector
education-sector

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Oct 12, 2025
Last Seen
Oct 29, 2025
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.