Kairos

Kairos — Threat Actor Profile | ObscureIQ
ObscureIQ Threat Intelligence · Actor Profile

KairosConfidence: Medium

Data theft / extortion
Also known as: Kairos V2

Motivation: Financial

2Attributed Breaches Circulating
MediumAttribution Confidence
Data theft / extortionActor Type

Overview

Focuses on exfiltration without encryption, active from 2024 against small-to-mid US healthcare, manufacturing, and business-services firms, with ~13 victims under Kairos and ~50 under Kairos V2 by mid-2025. Never confirmed to deploy an encryptor; a US government agency reportedly paid it ~$1M.

Tactics, Targeting & TTPs

Never confirmed to deploy an encryptor; pure hack-and-leak extortion. A US government agency reportedly paid it ~$1M.

Source

Attribution draws on public threat-intelligence reporting · Established (multi-source). Primary source →

Were you exposed in one of these breaches?

Check your exposure privately, or request a tailored exposure audit.

Request Consultation