kairos
Known ransomware group ACTIVE Currently active
Kairos is a data extortion group active since late 2024 that focuses solely on data theft with no encryption, primarily targeting small-to-mid-sized organizations in healthcare, manufacturing, and business services in the US, purchasing initial access from brokers and demanding Bitcoin payments.
1
Total Claims
0
Critical
—
Records Claimed
1
Industries Hit
Active span: May 29, 2026 – May 29, 2026 · 1 organizations targeted
Currently active
Actor Threat Profile
Activity Timeline
Peak: May 2026 (1)May 2026
LessMore
May 2026Top Targeted Industries
Public Sector 1
Tradecraft & Infrastructure
0
Documented tools
0 / 0
MITRE tactics / techniques
3
Known leak sites