Skip to content

Chaos

Chaos is a ransomware family and ransomware-as-a-service operation associated with double-extortion activity, including data theft followed by file encryption.

Profile source: Mallory opens in a new tab

Chaos

Family profile

Chaos is a ransomware family and ransomware-as-a-service operation associated with double-extortion activity, including data theft followed by file encryption. Reporting ties Chaos to financially motivated intrusions in which operators gain access through social engineering such as Microsoft Teams voice phishing, abuse remote-support and remote-management tools, establish persistence with custom malware, expand access across victim environments, and then deploy the encryptor across multiple endpoints in near-simultaneous fashion. Observed victimology includes North American organizations across services, manufacturing, energy, construction and engineering, and legal sectors, while broader reporting has also linked Chaos-derived variants to attacks against schools, small businesses, local governments, and individual users.

The current Chaos operation has been described as active since at least February 2025 and has been reported as linked to former members of the BlackSuit and Royal ecosystem. Separate reporting also notes an older Chaos builder lineage dating to 2021 that enabled low-skill actors to generate customized ransomware or trojanized variants, contributing to widespread reuse and confusion around the name. Some Chaos-based samples have exhibited persistence behavior and, in certain contexts, wiper-like destructive functionality rather than conventional monetization alone.

Chaos intrusions have been observed using a modular toolchain before encryption, including loaders, backdoors, alternate remote-access channels, and post-exploitation utilities for reconnaissance, persistence, lateral movement, and exfiltration. A Rust-based remote access trojan known as msaRAT has been attributed to the Chaos group and used prior to ransomware deployment. msaRAT is notable for hiding command-and-control inside legitimate Chrome or Edge browser activity by driving a headless browser through the Chrome DevTools Protocol and establishing encrypted communications over WebRTC, complicating network-based detection. Overall, Chaos represents both a ransomware family and an operational ecosystem that combines social engineering, hands-on-keyboard intrusion activity, data theft, and rapid enterprise-wide encryption.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Extortion
  • Initial Access
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 1, 2026
Last activity
Aug 6, 2026
Feed role
C2
Host form
3 IP / 0 hostnames

Leading locations

  • US2
  • HK1

Leading providers

  • ChangLian Network Technology Co., Limited1
  • Cox Communications Inc.1
  • XNNET LLC1

Infrastructure traits

  • Hosting 2

Samples

Recent associated samples

Reported operators

Threat actors

7 named in public reporting
STAC4749

Dans plusieurs incidents, l’accès établi a été exploité pour déployer le ransomware Chaos, combinant exfiltration de données et chiffrement.

MuddyWater

Threat actors are impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware in attacks targeting North American organizations.

Key Group

While the Chaos ransomware variant copied itself to $ user \ $ appdata \ cmd . exe and launched a new process, the new process in turn created a new file in the startup folder.

Twelve

We also found that in some cases, attackers used a Trojan made from a leaked builder for the Chaos ransomware to encrypt files.

CyberVolk

The CyberVolk collective is a prime example of how readily threat actors can access and deploy dangerous ransomware builders such as AzzaSec, Diamond, LockBit, Chaos and others.

Conti

A newly emerged ransomware-as-a-service (RaaS) gang called Chaos is likely made up of former members of the BlackSuit crew... Chaos, which sprang forth in February 2025...

Ke3chang

A newly emerged ransomware-as-a-service (RaaS) gang called Chaos is likely made up of former members of the BlackSuit crew... Chaos, which sprang forth in February 2025...

MITRE ATT&CK

Chaos in ATT&CK

48 distinct techniques

Reporting

Research mentioning Chaos

Jul 23
Security Affairs

Chaos ransomware deploys browser-based msaRAT to evade network detection - Security Affairs

Cisco Talos reported that the Chaos ransomware group is using a new Rust-based remote access trojan, msaRAT, to conceal command-and-control traffic inside legitimate browser activity. Instead of making direct outbound connections, the malware launches a headless Google Chrome or Microsoft Edge instance with the Chrome DevTools Protocol enabled, injects JavaScript, and uses the browser to establish a WebRTC DataChannel for encrypted communications. Talos said the malware combines WebRTC DTLS with its own ChaCha-Poly1305 encryption using an ECDH-derived shared key, giving operators covert tunneling, browser-assisted remote code execution, and asynchronous multi-threaded control. The reported intrusion chain begins with email or voice phishing, followed by the use of remote management software for persistence and delivery of an MSI installer disguised as a Windows update. That installer, identified as update_ms.msi, is downloaded over plain HTTP on port 443, extracts lib.dll, and loads it directly into memory before starting the browser in remote debugging mode. For signaling, the browser communicates with a Cloudflare Workers endpoint, while Twilio TURN infrastructure relays WebRTC traffic, a design that obscures attacker-controlled systems and makes network-based detection and attribution more difficult.

Jul 23
Cyber Security News

Chaos Ransomware Turns Your Chrome and Edge Web Browser Into an Invisible Malware Command Channel

Jul 23
The Hacker News

Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge

Jul 23
Malware News

Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel - Malware News - Malware Analysis, News and Indicators

Jul 23
Talosintelligence Other

Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel

Jul 23
Bleeping Computer

New msaRAT malware uses Chrome, Edge browsers to route C2 traffic

Jul 23
Help Net Security

Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process - Help Net Security

Mar 24
Sansec

Novel WebRTC skimmer bypasses security controls at $100+ billion car maker | Sansec

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.