FlagThis
← Threat Actors
/
unknown
/
Kairos Extortion Group
DOSSIER // KAIROS-EXTORTION-GROUP
Kairos Extortion Group
ACTIVE CAMPAIGN TRACKED
▲ High Threat
unknown
Primary Aliases:
Kairos V2
🔍 Adversary Rosetta Stone (1) ▾
📋 Copy All
Sponsor / State Affiliation
Independent / Not Attributed
Primary Motivation
financial (cyber extortion)
Active Timeline
Unknown – Present
Confidence Rating
85% (Grounded)
U.S. County Government Extortion, International Sector Targeting
📥 Export ATT&CK Layer (.json)
🔔 RSS Feed
🏛️ CISA Advisories ↗
📋 Copy Dossier Briefing
⚔️ Weaponized CVE Matrix
(0)
No specific weaponized CVEs currently mapped in the public baseline.
🎯 Target Sectors & Focus
Healthcare
Government
Financial Services
Manufacturing
Business Services
Education
Technology
🛡️ MITRE ATT&CK® Attack Lifecycle
(8 TTPs)
📥 Download Navigator JSON
All Stages
8
Initial Access
1
Credential Access & Discovery
1
Lateral Movement & Collection
1
Command & Control
1
Operational Techniques
4
Initial Access
1
T1566
Purchase of initial access from Initial Access Brokers (IABs)
↗
Credential Access & Discovery
1
T1003
Brute-force and password spraying attacks
↗
Lateral Movement & Collection
1
T1021
Exploitation of exposed Remote Desktop (RDP) Gateways
↗
Command & Control
1
T1071
Data exfiltration without encryption (pure extortion)
↗
Operational Techniques
4
T1000
Absence of MFA exploitation
↗
T1000
Tor-based chat portals for victim negotiation
↗
T1000
Peel chains and high-risk exchanges (e.g., Aifory Pro) for money laundering
↗
T1000
Targeted 'Big Game Hunting' focused on high-value data
↗
📰 Verified Campaigns & Intelligence Archive
🔔 Subscribe to Alerts
[DEEP DIVE]
Kairos Extortion Group: Data Exfiltration and Extortion of U.S. Government Entity
Attacks and Vulnerabilities
2026-07-06
Adversary Rosetta Stone // Kairos Extortion Group
×
🛡️ Other Industry Tracking Codes
Kairos V2
📋
Copied to clipboard
SHARE INTELLIGENCE WIRE
×
Story Title
X / Twitter
Bluesky
LinkedIn
Copy Link
LINK COPIED TO CLIPBOARD