Kairos is a financially motivated extortion group targeting US healthcare and demanding Bitcoin payments.
Analyst brief
Kairos is a financially motivated extortion group that surfaced with a data-leak site on 13 November 2024. It primarily targets the US healthcare sector, as well as Manufacturing, Professional Services, and Education sectors in the United States, New Zealand, Australia, and Canada. The group demands Bitcoin payments for the secure deletion of stolen files and threatens to leak data if victims do not comply. Defenders should focus on common extortion group TTPs like phishing and scanning for exposed internet-facing devices, and monitor for potential post-exploitation scripts linked to a Russian-language cybercriminal forum user.
Kairos
activeunknown
Kairos is an extortion group that emerged with a data-leak site on 13 November 2024, claiming attacks against six organizations, primarily in the US healthcare sector. The group is financially motivated, demanding Bitcoin payments for the secure deletion of stolen files and threatening to leak data if victims do not comply. While no specific TTPs are publicly known, common techniques among extortion groups include phishing and scanning for exposed internet-facing devices. There is a potential link to a user on a Russian-language cybercriminal forum who shares a post-exploitation script, but attribution remains uncertain.
Which sector does the Kairos group primarily target?+
It primarily targets the US healthcare sector, as well as Manufacturing, Professional Services, and Education sectors.
What tactics should defenders watch out for regarding the Kairos group?+
Defenders should focus on phishing, scanning for exposed internet-facing devices, and monitor for potential post-exploitation scripts linked to Russian-language cybercriminal forums.