ransomware.live: gruppo kairos
What it means
ransomware.live catalogo gruppi ha pubblicato l'advisory "ransomware.live: gruppo kairos". Occorre verificarne l'applicabilita rispetto a prodotti e servizi in uso.
Why it matters
Un advisory attendibile puo richiedere verifiche, aggiornamenti o mitigazioni, ma l'applicabilita va confermata sul perimetro reale.
Recommended actions
- Usare il profilo come contesto CTI difensivo e verificare gli avvistamenti con fonti indipendenti. Gli URL onion non sono stati contattati da EudorIA.
- Verificare tecnologie, versioni e servizi interessati nel proprio inventario.
- Consultare la fonte originale prima di pianificare la mitigazione.
Translation in progress
The official content is available in the original language. The Italian version will be published once automated checks are complete.
Text acquired from the source
Kairos is a data extortion group active since late 2024 that focuses solely on data theft with no encryption, primarily targeting small-to-mid-sized organizations in healthcare, manufacturing, and business services in the US, purchasing initial access from brokers and demanding Bitcoin payments.
- Source
- ransomware.live catalogo gruppi
- Publishing entity
- ransomware.live
- Entity type
- public index
- Area
- Global
- Original language
- en ยท translation in preparation
- Publication
- -
- Group attributed by the source
- kairos
Action indicated by the source
Usare il profilo come contesto CTI difensivo e verificare gli avvistamenti con fonti indipendenti. Gli URL onion non sono stati contattati da EudorIA.
Public onion references
URLs extracted from the public source. EudorIA has not contacted them nor downloaded content.
http://nerqnacjmdy3obvevyol7qhazkwkv57dwqvye5v46k5bcujtfa6sduad.onionhttp://kairosgeuzkzz3ajntqcyxl3ib36szz3mg62mb3zbui33pbk3uzo4qqd.onionhttp://erqnacjmdy3obvevyol7qhazkwkv57dwqvye5v46k5bcujtfa6sduad.onion