Skip to content

Chaos

Chaos is a .NET ransomware-builder family first observed in 2021.

Profile source: Mallory opens in a new tab

Chaos

Family profile

Chaos is a .NET ransomware-builder family first observed in 2021. Although marketed and commonly classified as ransomware, multiple variants behave primarily as wipers: they encrypt selected smaller files with AES-based routines but overwrite larger files with random data, making recovery impossible even where a decryptor might otherwise be available. Variants commonly enumerate drives and target user data, drop ransom notes, alter desktop wallpaper, delete Volume Shadow Copies and backup catalogs, and disable Windows recovery functionality to inhibit restoration. Chaos has been used as a foundation for related ransomware including Yashma, BlackSnake, and Spectra.

A Chaos variant was deployed in malicious fake Grand Theft Auto VI downloads aimed at gamers. The campaign used oversized game-image downloads, deceptive installers, Russian-language licensing-error decoys, SEO poisoning, gaming forums, social-media posts, and torrent sites. In that operation, Chaos was delivered alongside remote-access trojans and an information stealer, and acted as a destructive wiper rather than a viable extortion payload. The observed payload required administrative privileges for its recovery-inhibition and destructive activity, encrypted files up to 200 MB, and overwrote larger files. Russian-language lures suggest an emphasis on Russian-speaking users, but this distribution model can affect victims globally.

Capabilities

  • Defense Evasion

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 13, 2026
Last activity
Sep 16, 2026
Feed role
C2 / Distribution
Host form
5 IP / 0 hostnames

Leading locations

  • HK2
  • US2
  • CH1

Leading providers

  • ChangLian Network Technology Co., Limited1
  • Cox Communications Inc.1
  • DEDIK SERVICES LIMITED1
  • Hong Kong Communications International Co., Limited1
  • XNNET LLC1

Infrastructure traits

  • Hosting 3

Samples

Recent associated samples

Reported operators

Threat actors

8 named in public reporting
Asha Hacker Team

“The most damaging piece is a Chaos ransomware variant... the actors are not looking to collect a ransom from infected users. Instead, they encrypt and/or destroy files on the system, effectively utilizing the ransomware as a wiper.”

MuddyWater

MuddyWater, a hacking and cyber espionage group associated with Iran’s Ministry of Intelligence and Security, posed as the Chaos ransomware group to hide its espionage activity.

STAC4749

Dans plusieurs incidents, l’accès établi a été exploité pour déployer le ransomware Chaos, combinant exfiltration de données et chiffrement.

Key Group

While the Chaos ransomware variant copied itself to $ user \ $ appdata \ cmd . exe and launched a new process, the new process in turn created a new file in the startup folder.

Twelve

We also found that in some cases, attackers used a Trojan made from a leaked builder for the Chaos ransomware to encrypt files.

CyberVolk

The CyberVolk collective is a prime example of how readily threat actors can access and deploy dangerous ransomware builders such as AzzaSec, Diamond, LockBit, Chaos and others.

Conti

A newly emerged ransomware-as-a-service (RaaS) gang called Chaos is likely made up of former members of the BlackSuit crew... Chaos, which sprang forth in February 2025...

Ke3chang

A newly emerged ransomware-as-a-service (RaaS) gang called Chaos is likely made up of former members of the BlackSuit crew... Chaos, which sprang forth in February 2025...

Exploited software

Vulnerabilities linked to Chaos

1 CVEs

MITRE ATT&CK

Chaos in ATT&CK

68 distinct techniques

Techniques

68 techniques
T1204.002 Malicious File T1486 Data Encrypted for Impact T1485 Data Destruction T1036 Masquerading T1490 Inhibit System Recovery T1608.006 SEO Poisoning T1068 Exploitation for Privilege Escalation T1095 Non-Application Layer Protocol T1573 Encrypted Channel T1083 File and Directory Discovery T1005 Data from Local System T1027 Obfuscated Files or Information T1190 Exploit Public-Facing Application T1049 System Network Connections Discovery T1059.003 Windows Command Shell T1106 Native API T1071 Application Layer Protocol T1547 Boot or Logon Autostart Execution T1135 Network Share Discovery T1489 Service Stop T1016 System Network Configuration Discovery T1091 Replication Through Removable Media T1090.001 Internal Proxy T1110.001 Password Guessing T1218 System Binary Proxy Execution T1059.004 Unix Shell T1543.002 Systemd Service T1498 Network Denial of Service T1105 Ingress Tool Transfer T1203 Exploitation for Client Execution T1222 File and Directory Permissions Modification T1070.004 File Deletion T1528 Steal Application Access Token T1219 Remote Access Tools T1566.003 Spearphishing via Service T1003 OS Credential Dumping T1537 Transfer Data to Cloud Account T1567 Exfiltration Over Web Service T1566 Phishing T1078 Valid Accounts T1041 Exfiltration Over C2 Channel T1547.001 Registry Run Keys / Startup Folder T1547.009 Shortcut Modification T1484.001 Group Policy Modification T1053.005 Scheduled Task T1033 System Owner/User Discovery T1491.001 Internal Defacement T1021 Remote Services T1090 Proxy T1110 Brute Force T1070 Indicator Removal T1059 Command and Scripting Interpreter T1496 Resource Hijacking T1090.003 Multi-hop Proxy T1021.004 SSH T1021.002 SMB/Windows Admin Shares T1573.001 Symmetric Cryptography T1021.007 Cloud Services T1566.002 Spearphishing Link T1047 Windows Management Instrumentation T1562.001 Disable or Modify Tools T1082 System Information Discovery T1098 Account Manipulation T1021.001 Remote Desktop Protocol T1218.007 Msiexec T1059.001 PowerShell T1205 Traffic Signaling T1104 Multi-Stage Channels

Reporting

Research mentioning Chaos

Aug 5
Cloud Security Alliance

New Chaos Malware Variant Exploiting Misconfigurations | CSA

Researchers reported that a new Chaos malware variant was deployed through a misconfigured Apache Hadoop instance, where an attacker abused an application-creation endpoint to execute shell commands, download a 64-bit ELF payload from pan.tenire[.]com, run it, and then remove it from disk. The intrusion, observed in Darktrace’s CloudyPots honeypot environment, shows Chaos moving beyond its earlier focus on routers and into Linux cloud-server compromises. The sample was identified as an evolved form of the Go-based Chaos malware previously described as a multi-purpose "Swiss army knife" threat. It retained DDoS and persistence functions while adding a SOCKS5 proxy capability and dropping some older spreading and exploitation features. Analysts said it established persistence with systemd, used a keep-alive script at /boot/system.pub, and relied on the embedded domain gmserver.osfc[.]org[.]cn for command-and-control resolution over port 65111, underscoring the risk posed by exposed or misconfigured cloud services.

Jul 23
Security Affairs

Chaos ransomware deploys browser-based msaRAT to evade network detection - Security Affairs

Cisco Talos reported that the Chaos ransomware group is using a new Rust-based remote access trojan, msaRAT, to conceal command-and-control traffic inside legitimate browser activity. Instead of making direct outbound connections, the malware launches a headless Google Chrome or Microsoft Edge instance with the Chrome DevTools Protocol enabled, injects JavaScript, and uses the browser to establish a WebRTC DataChannel for encrypted communications. Talos said the malware combines WebRTC DTLS with its own ChaCha-Poly1305 encryption using an ECDH-derived shared key, giving operators covert tunneling, browser-assisted remote code execution, and asynchronous multi-threaded control. The reported intrusion chain begins with email or voice phishing, followed by the use of remote management software for persistence and delivery of an MSI installer disguised as a Windows update. That installer, identified as update_ms.msi, is downloaded over plain HTTP on port 443, extracts lib.dll, and loads it directly into memory before starting the browser in remote debugging mode. For signaling, the browser communicates with a Cloudflare Workers endpoint, while Twilio TURN infrastructure relays WebRTC traffic, a design that obscures attacker-controlled systems and makes network-based detection and attribution more difficult.

Jul 23
Cyber Security News

Chaos Ransomware Turns Your Chrome and Edge Web Browser Into an Invisible Malware Command Channel

Jul 23
The Hacker News

Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge

Jul 23
Malware News

Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel - Malware News - Malware Analysis, News and Indicators

Jul 23
Talosintelligence Other

Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel

Jul 23
Bleeping Computer

New msaRAT malware uses Chrome, Edge browsers to route C2 traffic

Jul 23
Help Net Security

Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process - Help Net Security

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.