Kairos Ransomware: Data-Extortion Case Study Involving a U.S. Government Entity
ID: c6516a78-6e27-5d9c-ab9e-e8fc17888232
STIX ID: report--c6516a78-6e27-5d9c-ab9e-e8fc17888232
Feed Name: Ransomware ISAC Blog
This report analyzes a successful $1M ransom payment by a U.S. government body to a data-extortion actor named Kairos, who claimed possession of ~2 TB / 1.6M files; it reconstructs the leaked negotiation transcript, documents the staged demands and deadline pressure, traces post-payment BTC flows to exchange-associated addresses (ByBit, OKX, BELQI), and concludes the actor is an unverified ransomware-branded data-extortion group with no confirmed encryptor or independent proof of deletion.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
