Skip to content

Chaos

Chaos is a Windows ransomware family and ransomware-as-a-service operation active since at least 2025, with reporting also linking the broader Chaos builder lineage to earlier ransomware activity dating back to 2021.

Profile source: Mallory opens in a new tab

Chaos

Family profile

Chaos is a Windows ransomware family and ransomware-as-a-service operation active since at least 2025, with reporting also linking the broader Chaos builder lineage to earlier ransomware activity dating back to 2021. It has been used in financially motivated intrusions that combine data theft and file encryption, including rapid post-compromise deployments across multiple endpoints. In observed enterprise attacks, operators commonly obtain access through social engineering such as Microsoft Teams voice phishing or through spam and other phishing activity, then use remote-support or remote-management tools to establish control, conduct reconnaissance, expand access, and stage ransomware execution. Reported intrusions associated with Chaos have included pre-encryption use of custom loaders, backdoors, Python-based implants, Golang tools, and the Rust-based msaRAT remote access trojan.

Chaos-associated operators have demonstrated double-extortion behavior, with exfiltration preceding encryption in some incidents and public leak threats used to pressure victims. The malware has been deployed in near-simultaneous fashion across endpoints after attackers established broader access in victim environments. Associated tradecraft includes persistence, reconnaissance, lateral movement via Remote Desktop Protocol and secondary remote-access channels, and defense evasion through frequent changes to filenames, persistence methods, and deployment chains. One documented Chaos-linked implant, msaRAT, hides command-and-control traffic inside legitimate Chrome or Edge browser activity by driving a headless browser through the Chrome DevTools Protocol and establishing encrypted communications over WebRTC.

Victimology tied to Chaos activity includes North American organizations across services, manufacturing, energy, construction and engineering, and legal services, while other reporting on the builder ecosystem shows use by a wider range of actors against smaller organizations and individuals. Chaos has also been linked in some reporting to former BlackSuit and Royal affiliates, though attribution at the operator level varies by intrusion. The family is best characterized as a ransomware platform and ecosystem used by multiple actors with differing sophistication, ranging from commodity builder-based deployments to more mature double-extortion operations.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Extortion
  • Lateral Movement
  • Persistence
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 29, 2026
Last activity
Aug 2, 2026
Feed role
C2 / Distribution
Host form
6 IP / 0 hostnames

Leading locations

  • HK2
  • US2
  • CA1
  • CH1

Leading providers

  • ChangLian Network Technology Co., Limited1
  • Cox Communications Inc.1
  • DEDIK SERVICES LIMITED1
  • Hong Kong Communications International Co., Limited1
  • OVH SAS1
  • XNNET LLC1

Infrastructure traits

  • Hosting 4

Samples

Recent associated samples

Reported operators

Threat actors

7 named in public reporting
STAC4749

Dans plusieurs incidents, l’accès établi a été exploité pour déployer le ransomware Chaos, combinant exfiltration de données et chiffrement.

MuddyWater

Threat actors are impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware in attacks targeting North American organizations.

Key Group

While the Chaos ransomware variant copied itself to $ user \ $ appdata \ cmd . exe and launched a new process, the new process in turn created a new file in the startup folder.

Twelve

We also found that in some cases, attackers used a Trojan made from a leaked builder for the Chaos ransomware to encrypt files.

CyberVolk

The CyberVolk collective is a prime example of how readily threat actors can access and deploy dangerous ransomware builders such as AzzaSec, Diamond, LockBit, Chaos and others.

Conti

A newly emerged ransomware-as-a-service (RaaS) gang called Chaos is likely made up of former members of the BlackSuit crew... Chaos, which sprang forth in February 2025...

Ke3chang

A newly emerged ransomware-as-a-service (RaaS) gang called Chaos is likely made up of former members of the BlackSuit crew... Chaos, which sprang forth in February 2025...

MITRE ATT&CK

Chaos in ATT&CK

48 distinct techniques

Reporting

Research mentioning Chaos

Jul 23
Security Affairs

Chaos ransomware deploys browser-based msaRAT to evade network detection - Security Affairs

Cisco Talos reported that the Chaos ransomware group is using a new Rust-based remote access trojan, msaRAT, to conceal command-and-control traffic inside legitimate browser activity. Instead of making direct outbound connections, the malware launches a headless Google Chrome or Microsoft Edge instance with the Chrome DevTools Protocol enabled, injects JavaScript, and uses the browser to establish a WebRTC DataChannel for encrypted communications. Talos said the malware combines WebRTC DTLS with its own ChaCha-Poly1305 encryption using an ECDH-derived shared key, giving operators covert tunneling, browser-assisted remote code execution, and asynchronous multi-threaded control. The reported intrusion chain begins with email or voice phishing, followed by the use of remote management software for persistence and delivery of an MSI installer disguised as a Windows update. That installer, identified as update_ms.msi, is downloaded over plain HTTP on port 443, extracts lib.dll, and loads it directly into memory before starting the browser in remote debugging mode. For signaling, the browser communicates with a Cloudflare Workers endpoint, while Twilio TURN infrastructure relays WebRTC traffic, a design that obscures attacker-controlled systems and makes network-based detection and attribution more difficult.

Jul 23
Cyber Security News

Chaos Ransomware Turns Your Chrome and Edge Web Browser Into an Invisible Malware Command Channel

Jul 23
The Hacker News

Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge

Jul 23
Malware News

Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel - Malware News - Malware Analysis, News and Indicators

Jul 23
Talosintelligence Other

Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel

Jul 23
Bleeping Computer

New msaRAT malware uses Chrome, Edge browsers to route C2 traffic

Jul 23
Help Net Security

Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process - Help Net Security

Mar 24
Sansec

Novel WebRTC skimmer bypasses security controls at $100+ billion car maker | Sansec

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.