Chaos is a ransomware-as-a-service (RaaS) operation active since at least February 2025 and associated with double-extortion intrusions against large organizations. The group has been linked to financially motivated campaigns that use spam email, voice phishing, and Microsoft Teams-based social engineering for initial access, often by impersonating IT support personnel and persuading victims to grant remote assistance through legitimate remote-management tools. After access is obtained, operators have used PowerShell-delivered malware, custom loaders, Python and Rust-based backdoors, secondary remote-access channels, reverse proxy tooling, and remote administration software to maintain access, conduct reconnaissance, enable lateral movement, and prepare ransomware deployment. At least some intrusions involved data theft prior to encryption. A notable tool attributed to Chaos is msaRAT, a Rust-based remote access trojan used post-compromise and prior to ransomware execution. msaRAT avoids direct outbound communications from the malware process by launching Chrome or Microsoft Edge in headless mode, controlling the browser through the Chrome DevTools Protocol, and tunneling command-and-control over WebRTC. This browser-mediated design uses legitimate web infrastructure for signaling and relay, blends malicious traffic into normal browser activity, and materially improves defense evasion while supporting remote command execution and data movement. Chaos has operated a dedicated leak site and has publicly claimed victims in multiple countries, including the United States, United Kingdom, Canada, and Russia. Reported victim sectors include health care, technology, professional services, transportation and logistics, retail-related distribution, education, manufacturing, energy, and construction and engineering. The group has been assessed as part of a broader ransomware ecosystem and has been described as linked to former members of the BlackSuit and Royal ransomware gangs. The Chaos name has also been abused by other actors as cover. Iran-linked MuddyWater has been reported to pose as Chaos in order to disguise espionage activity as financially motivated ransomware, including use of extortion notes, negotiation channels, and leak-site branding. Separately, actors identifying as Desorden have claimed to be former associates of Chaos. The 2025-era Chaos RaaS operation is distinct from the older and unrelated Chaos ransomware family.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware-as-a-Service group operating a dedicated leak site and claiming a data theft/extortion incident involving Healthcare Highways, including an alleged dump of 235 GB of PHI and internal documents.
Chaos branding covered both a conventional financially motivated RaaS operation and a separate state-sponsored espionage campaign, illustrating how ransomware branding can be used as cover and complicate attribution.
Conducting a ransomware attack and data extortion operation against Tomorrow’s Office, with claims of exfiltrating 125 GB of confidential data and an ongoing data publication countdown.
Conducting a ransomware/data leak extortion attack against Healthcare Highways, with a 24-hour deadline and a claimed 235 GB cache of sensitive company and client records.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.