Last seven days
- First activity
- Jul 29, 2026
- Last activity
- Aug 2, 2026
- Feed role
- C2 / Distribution
- Host form
- 6 IP / 0 hostnames
Chaos is a Windows ransomware family and ransomware-as-a-service operation active since at least 2025, with reporting also linking the broader Chaos builder lineage to earlier ransomware activity dating back to 2021.
Profile source: Mallory opens in a new tabChaos
Chaos is a Windows ransomware family and ransomware-as-a-service operation active since at least 2025, with reporting also linking the broader Chaos builder lineage to earlier ransomware activity dating back to 2021. It has been used in financially motivated intrusions that combine data theft and file encryption, including rapid post-compromise deployments across multiple endpoints. In observed enterprise attacks, operators commonly obtain access through social engineering such as Microsoft Teams voice phishing or through spam and other phishing activity, then use remote-support or remote-management tools to establish control, conduct reconnaissance, expand access, and stage ransomware execution. Reported intrusions associated with Chaos have included pre-encryption use of custom loaders, backdoors, Python-based implants, Golang tools, and the Rust-based msaRAT remote access trojan.
Chaos-associated operators have demonstrated double-extortion behavior, with exfiltration preceding encryption in some incidents and public leak threats used to pressure victims. The malware has been deployed in near-simultaneous fashion across endpoints after attackers established broader access in victim environments. Associated tradecraft includes persistence, reconnaissance, lateral movement via Remote Desktop Protocol and secondary remote-access channels, and defense evasion through frequent changes to filenames, persistence methods, and deployment chains. One documented Chaos-linked implant, msaRAT, hides command-and-control traffic inside legitimate Chrome or Edge browser activity by driving a headless browser through the Chrome DevTools Protocol and establishing encrypted communications over WebRTC.
Victimology tied to Chaos activity includes North American organizations across services, manufacturing, energy, construction and engineering, and legal services, while other reporting on the builder ecosystem shows use by a wider range of actors against smaller organizations and individuals. Chaos has also been linked in some reporting to former BlackSuit and Royal affiliates, though attribution at the operator level varies by intrusion. The family is best characterized as a ransomware platform and ecosystem used by multiple actors with differing sophistication, ranging from commodity builder-based deployments to more mature double-extortion operations.
C2 tracking
Derp observations, rolling seven-day window
Samples
0f78a658b60f0879acccf0933d9ae8a5d2c188e9f16b8e6f7b01bd0cc9b5c4e1 27215e26b312b8b4f8fc51bdcea6741536dafc9267348284e2259e798aed0e4d 3755718db9d33f4aba2563de454d4530a308b41b1096c904102d08e2101f2020 4e5cebe1908e12e8a4ed1198fb01fb87871dbe54847855b11b3540dbc47bbe88 738eacc140159cd81dff41dd16c806eb7c0c8391c256f1738d75d0321f77ba2e Reported operators
Dans plusieurs incidents, l’accès établi a été exploité pour déployer le ransomware Chaos, combinant exfiltration de données et chiffrement.
Threat actors are impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware in attacks targeting North American organizations.
While the Chaos ransomware variant copied itself to $ user \ $ appdata \ cmd . exe and launched a new process, the new process in turn created a new file in the startup folder.
We also found that in some cases, attackers used a Trojan made from a leaked builder for the Chaos ransomware to encrypt files.
The CyberVolk collective is a prime example of how readily threat actors can access and deploy dangerous ransomware builders such as AzzaSec, Diamond, LockBit, Chaos and others.
A newly emerged ransomware-as-a-service (RaaS) gang called Chaos is likely made up of former members of the BlackSuit crew... Chaos, which sprang forth in February 2025...
A newly emerged ransomware-as-a-service (RaaS) gang called Chaos is likely made up of former members of the BlackSuit crew... Chaos, which sprang forth in February 2025...
MITRE ATT&CK
Reporting
Cisco Talos reported that the Chaos ransomware group is using a new Rust-based remote access trojan, msaRAT, to conceal command-and-control traffic inside legitimate browser activity. Instead of making direct outbound connections, the malware launches a headless Google Chrome or Microsoft Edge instance with the Chrome DevTools Protocol enabled, injects JavaScript, and uses the browser to establish a WebRTC DataChannel for encrypted communications. Talos said the malware combines WebRTC DTLS with its own ChaCha-Poly1305 encryption using an ECDH-derived shared key, giving operators covert tunneling, browser-assisted remote code execution, and asynchronous multi-threaded control. The reported intrusion chain begins with email or voice phishing, followed by the use of remote management software for persistence and delivery of an MSI installer disguised as a Windows update. That installer, identified as update_ms.msi, is downloaded over plain HTTP on port 443, extracts lib.dll, and loads it directly into memory before starting the browser in remote debugging mode. For signaling, the browser communicates with a Cloudflare Workers endpoint, while Twilio TURN infrastructure relays WebRTC traffic, a design that obscures attacker-controlled systems and makes network-based detection and attribution more difficult.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.