Ransomware Group intelligence
Kairos
ActiveTrack Kairos with 102 published victims and 3 known leak locations in a single intelligence view.
Overview
Kairos is tracked by Breach House as a ransomware group with 102 published victims.
United States is currently the most targeted country in this dataset.
3 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (3)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 3 | Onion service | Up checked 1h ago | kairosgeuzkzz3ajntqcyxl3ib36szz3mg62mb3zbui33pbk3uzo4qqd.onion |
| Leak location 2 | Onion service | Down checked 1h ago | nerqnacjmdy3obvevyol7qhazkwkv57dwqvye5v46k5bcujtfa6sduad.onion |
| Leak location 1 | Onion service | Down checked 1h ago | erqnacjmdy3obvevyol7qhazkwkv57dwqvye5v46k5bcujtfa6sduad.onion |
Top Activity Sectors (14)
- Not identified 29
- Healthcare / Pharma 12
- Education 10
- Manufacturing / Engineering 6
- Finance / Legal / Insurance 6
- Public Sector 6
- Services 6
- Construction / Real Estate 5
- Communication / Marketing 5
- Hospitality / Food & Beverage / Tourism 3
- Retail / E-commerce 2
- Transportation / Travel / Logistics 2
- Energy 2
- NGOs / Associations 1
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Kairos, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: kairos executes PowerShell scripts to stage payloads and manipulate system processes during initial compromise.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: kairos adds malicious registry run keys to ensure persistence across reboots on compromised systems.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: kairos disables antivirus tools by terminating security processes and modifying Windows Defender settings.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.016 Junk Code Insertion Stealth
What they do: kairos inserts junk code into legitimate binaries to evade static malware analysis tools.
What that means: Adversaries may use junk code / dead code to obfuscate a malware’s functionality.
-
T1070.004 File Deletion Stealth
What they do: kairos deletes Volume Shadow Copies via vssadmin /delete command to prevent system recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: kairos discovers remote systems via SMB enumeration to map the internal network before spreading.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1135 Network Share Discovery Discovery
What they do: kairos scans network shares using net use commands to identify additional victims for lateral movement.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: kairos exfiltrates stolen data using encrypted channels before deploying ransomware to preserve leverage.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: kairos encrypts victim files using a custom ransomware binary targeting Documents and Images directories.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: kairos invokes system shutdown commands to disrupt recovery operations and maximize operational impact.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
README_47.txt
██╗░░██╗░█████╗░██╗██████╗░░█████╗░░██████╗
██║░██╔╝██╔══██╗██║██╔══██╗██╔══██╗██╔════╝
█████═╝░███████║██║██████╔╝██║░░██║╚█████╗░
██╔═██╗░██╔══██║██║██╔══██╗██║░░██║░╚═══██╗
██║░╚██╗██║░░██║██║██║░░██║╚█████╔╝██████╔╝
╚═╝░░╚═╝╚═╝░░╚═╝╚═╝╚═╝░░╚═╝░╚════╝░╚═════╝░
Your security was breached, allowing us to control your network for WEEKS.
We are not a politically motivated group and we want nothing more than money.
We have downloaded your most SENSITIVE DATA -- if you do not pay, everything will be PUBLISHED and/or SOLD to a third party.
We collect the most valuable and harmful data, such as:
- Accounting, Finance, Banking, Billing, Statements, HR, Payrolls
- Legal, Audit & Revenue Reports, Budgets
- Backups, Source Codes, Credentials, Databases with private data
- Agreements, NDA, Corporate Contracts, WorkFiles, Employee's private info and agreements, Tax and IRS files
- Private Correspondence of your Executive Team
- SSN/Address/Phones/Emails/Driver Licenses/Signatures/Photos/Medical history/etc
- Any other files with personal & private data
The PUBLICATION of THIS DATA will lead to DISASTROUS CONSEQUENCES for your business
NEXT STEPS & IMPORTANT NOTES
CONTACT US As Soon As Possible
Now, in order to start negotiations, you need to do the following:
- install and run 'Tor Browser' from https://www.torproject.org/download/
- use 'Tor Browser' open http://nerqnacjmdy3obvevyol7qhazkwkv57dwqvye5v46k5bcujtfa6sduad.onion/
- enter your Token ID: [snip]
MAKING a DEAL with us ELIMINATES RISK of PUBLIC DATA DISCLOSURE & LEAKAGE -- we DELETE your info.
ABSENCE of CONTACT within 3 DAYS leads to FAIL of negotiations & START of DATA PUBLICATION
YOU'RE IT OFFICER
Immediately INFORM your executives and show them this file
Help them to CONTACT with us & be in touch
REMEMBER: attempt to hide attack or lie to executives always leads to job loss
YOU'RE REGULAR STAFF
DO NOT panic and DO NOT DISCLOSE ANY INFO to third-parties
REMEMBER: investigation always finds an employee-the source of leak
YOU'RE THE DECISION MAKER
Do not worry. Making a deal with us helps to fix everything and get up & running FAST.
An incomplete list of risks you are facing in case of non-payment:
- Loss of customer trust and loyalty.
- Damage to the company's reputation.
- Legal consequences and compliance fines.
- Financial losses and costs associated with data recovery.
- Impact on competitive advantage and market share.
- Breach of data privacy regulations and laws.
- Disruption of business operations.
- Reduced employee morale and productivity.
- Potential for intellectual property theft.
- Loss of trade secrets and proprietary information.
We will also attack your partners and suppliers using info obtained from your network
It can lead to legal actions against you for data breaches/
If you will not contact us in a timely manner we will start notifying your employees, clients, partners, subcontractors
and any other persons that should know how you treat your own corporate secrets and theirs.
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (102)
Search, filter and paginate the victim timeline for Kairos. Showing 101–102 of 102.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | pmrcenter.com id15280 View details | United States | Healthcare / Pharma | ||
|
usa - The Physical Medicine and Rehabilitation Center |
|||||
| Ransomware | kansasrmc.com id15279 View details | United States | Healthcare / Pharma | ||
|
usa - Kansas Regenerative medicine centre |
|||||