Chaos is a financially motivated ransomware-as-a-service operation first observed recruiting affiliates in February 2025, with public data-leak activity beginning in March 2025. Also known as Chaos ransomware and the Chaos ransomware group, it operates an open affiliate program. It is distinct from the unrelated Chaos ransomware builder introduced in 2021. Its targets are predominantly U.S. organizations across manufacturing, technology, financial services, healthcare, business services, and transportation, with additional targeting reported in the United Kingdom and Taiwan. Chaos combines data theft and file encryption with threats to publish stolen information and launch distributed denial-of-service attacks, forming a triple-extortion model. It maintains a data-leak site and offers AI chat agents to assist with extortion negotiations. Its encryption platform supports selective partial-file encryption and uses Curve25519 ECDH and AES-256 with per-file keys. The operation offers encryption capabilities targeting Windows, Linux, ESXi, and NAS environments. Common initial-access methods include email flooding followed by voice phishing, impersonation of IT or security personnel, and persuasion of victims to grant Microsoft Quick Assist access. Operators deploy legitimate remote-management products for redundant access and use reverse SSH tunnels for command and control. Post-compromise activity includes Active Directory and domain-trust enumeration, network scanning, credential dumping with Mimikatz, extraction of Windows credential material, Kerberoasting, account manipulation, and token impersonation. Lateral movement uses RDP, SMB, WMI, and remote-management tools. Chaos uses GoodSync for data exfiltration, prioritizes valuable business documents, and impairs defenses and recovery by disguising binaries, clearing logs, removing security products, deleting shadow copies, and modifying recovery settings.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
34 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
7 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Chaos claims to have published 1,500 GB of Astrana Health, Inc. data, including data and diagnoses of millions of patients, after the company's management allegedly withdrew from an extortion deal. The victim was listed as discovered on October 9, 2026; no ransom amount or payment deadline is stated.
Chaos claimed to have stolen 500 GB of data from NSE Insurance Agencies, a California insurance agency. NSE confirmed unauthorized network access between November 6 and November 29, 2025, and potential acquisition of files containing sensitive customer information. The content does not independently verify Chaos's responsibility or its claimed theft volume, and does not establish that ransomware encryption occurred.
The Chaos ransomware operation claims to have breached Park Dental, a UK healthcare/dental organization operating at parkdental.com. The group states that prior contact attempts were ignored and threatens full publication of stolen data unless management responds within 24 hours; no data volume, ransom amount, or sample evidence is provided in the available post excerpt.
Allegedly conducted a ransomware/data-extortion attack against Advantech, claiming to have exfiltrated data and threatening to publish the full dataset after publishing a partial sample.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.