Last seven days
- First activity
- Sep 13, 2026
- Last activity
- Sep 16, 2026
- Feed role
- C2 / Distribution
- Host form
- 5 IP / 0 hostnames
Chaos is a .NET ransomware-builder family first observed in 2021.
Profile source: Mallory opens in a new tabChaos
Chaos is a .NET ransomware-builder family first observed in 2021. Although marketed and commonly classified as ransomware, multiple variants behave primarily as wipers: they encrypt selected smaller files with AES-based routines but overwrite larger files with random data, making recovery impossible even where a decryptor might otherwise be available. Variants commonly enumerate drives and target user data, drop ransom notes, alter desktop wallpaper, delete Volume Shadow Copies and backup catalogs, and disable Windows recovery functionality to inhibit restoration. Chaos has been used as a foundation for related ransomware including Yashma, BlackSnake, and Spectra.
A Chaos variant was deployed in malicious fake Grand Theft Auto VI downloads aimed at gamers. The campaign used oversized game-image downloads, deceptive installers, Russian-language licensing-error decoys, SEO poisoning, gaming forums, social-media posts, and torrent sites. In that operation, Chaos was delivered alongside remote-access trojans and an information stealer, and acted as a destructive wiper rather than a viable extortion payload. The observed payload required administrative privileges for its recovery-inhibition and destructive activity, encrypted files up to 200 MB, and overwrote larger files. Russian-language lures suggest an emphasis on Russian-speaking users, but this distribution model can affect victims globally.
C2 tracking
Derp observations, rolling seven-day window
Samples
0f78a658b60f0879acccf0933d9ae8a5d2c188e9f16b8e6f7b01bd0cc9b5c4e1 3755718db9d33f4aba2563de454d4530a308b41b1096c904102d08e2101f2020 4e5cebe1908e12e8a4ed1198fb01fb87871dbe54847855b11b3540dbc47bbe88 738eacc140159cd81dff41dd16c806eb7c0c8391c256f1738d75d0321f77ba2e c2e9fbca414575d5c080d97f378024a4d131d6e1262112aebaa96eafa3592381 27215e26b312b8b4f8fc51bdcea6741536dafc9267348284e2259e798aed0e4d Reported operators
“The most damaging piece is a Chaos ransomware variant... the actors are not looking to collect a ransom from infected users. Instead, they encrypt and/or destroy files on the system, effectively utilizing the ransomware as a wiper.”
MuddyWater, a hacking and cyber espionage group associated with Iran’s Ministry of Intelligence and Security, posed as the Chaos ransomware group to hide its espionage activity.
Dans plusieurs incidents, l’accès établi a été exploité pour déployer le ransomware Chaos, combinant exfiltration de données et chiffrement.
While the Chaos ransomware variant copied itself to $ user \ $ appdata \ cmd . exe and launched a new process, the new process in turn created a new file in the startup folder.
We also found that in some cases, attackers used a Trojan made from a leaked builder for the Chaos ransomware to encrypt files.
The CyberVolk collective is a prime example of how readily threat actors can access and deploy dangerous ransomware builders such as AzzaSec, Diamond, LockBit, Chaos and others.
A newly emerged ransomware-as-a-service (RaaS) gang called Chaos is likely made up of former members of the BlackSuit crew... Chaos, which sprang forth in February 2025...
A newly emerged ransomware-as-a-service (RaaS) gang called Chaos is likely made up of former members of the BlackSuit crew... Chaos, which sprang forth in February 2025...
Exploited software
MITRE ATT&CK
Reporting
Researchers reported that a new Chaos malware variant was deployed through a misconfigured Apache Hadoop instance, where an attacker abused an application-creation endpoint to execute shell commands, download a 64-bit ELF payload from pan.tenire[.]com, run it, and then remove it from disk. The intrusion, observed in Darktrace’s CloudyPots honeypot environment, shows Chaos moving beyond its earlier focus on routers and into Linux cloud-server compromises. The sample was identified as an evolved form of the Go-based Chaos malware previously described as a multi-purpose "Swiss army knife" threat. It retained DDoS and persistence functions while adding a SOCKS5 proxy capability and dropping some older spreading and exploitation features. Analysts said it established persistence with systemd, used a keep-alive script at /boot/system.pub, and relied on the embedded domain gmserver.osfc[.]org[.]cn for command-and-control resolution over port 65111, underscoring the risk posed by exposed or misconfigured cloud services.
Cisco Talos reported that the Chaos ransomware group is using a new Rust-based remote access trojan, msaRAT, to conceal command-and-control traffic inside legitimate browser activity. Instead of making direct outbound connections, the malware launches a headless Google Chrome or Microsoft Edge instance with the Chrome DevTools Protocol enabled, injects JavaScript, and uses the browser to establish a WebRTC DataChannel for encrypted communications. Talos said the malware combines WebRTC DTLS with its own ChaCha-Poly1305 encryption using an ECDH-derived shared key, giving operators covert tunneling, browser-assisted remote code execution, and asynchronous multi-threaded control. The reported intrusion chain begins with email or voice phishing, followed by the use of remote management software for persistence and delivery of an MSI installer disguised as a Windows update. That installer, identified as update_ms.msi, is downloaded over plain HTTP on port 443, extracts lib.dll, and loads it directly into memory before starting the browser in remote debugging mode. For signaling, the browser communicates with a Cloudflare Workers endpoint, while Twilio TURN infrastructure relays WebRTC traffic, a design that obscures attacker-controlled systems and makes network-based detection and attribution more difficult.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.