Chaos ransomware is a Windows-targeting, .NET-based ransomware family associated with a customizable builder first sold in June 2021. The builder enables operators to customize ransom messages, encrypted-file extensions, and other infection settings. Related variants include WannaFriendMe, which impersonates Ryuk and demanded payment through a Roblox Game Pass, and Yashma, a rebranded derivative with improved support for encrypting larger files.
Chaos combines file encryption with destructive overwriting. Earlier versions encrypted only small files and replaced larger files with random data, making those files unrecoverable even with a decryptor. File-size thresholds vary by version. A variant distributed through fake Grand Theft Auto VI downloads encrypts files of 200 MB or less and overwrites larger files. This variant functions as a wiper rather than a conventional extortion payload, leaving messages without a viable payment or recovery mechanism. When executed with administrator privileges, it deletes volume shadow copies and disables Windows recovery options. Its targets include user documents, non-system drives, shared-data locations, and cloud-synchronized folders.
Observed distribution campaigns target gamers through deceptive game downloads promoted using SEO poisoning, gaming forums, torrent sites, and social media. Fake installers deploy Chaos alongside separate remote-access trojans and information stealers; those companion payloads' surveillance and theft capabilities are not intrinsic Chaos capabilities.
The builder-based family is distinct from the Chaos ransomware-as-a-service operation first observed recruiting in 2025. Unrelated malware also uses the Chaos name, including a Kaiji-derived botnet and CHAOS RAT; their capabilities should not be conflated with this ransomware family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The affected package is github.com/tiagorlampert/CHAOS v5.0.1; the referenced exploit is described as "Chaos RAT XSS to RCE."
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Chaos only offers some automation and AI through chat agents that assist with extortion negotiations, but these do not have a direct impact on the ransomware’s capabilities.
“The most damaging piece is a Chaos ransomware variant... the actors are not looking to collect a ransom from infected users. Instead, they encrypt and/or destroy files on the system, effectively utilizing the ransomware as a wiper.”
MuddyWater, a hacking and cyber espionage group associated with Iran’s Ministry of Intelligence and Security, posed as the Chaos ransomware group to hide its espionage activity.
Dans plusieurs incidents, l’accès établi a été exploité pour déployer le ransomware Chaos, combinant exfiltration de données et chiffrement.
While the Chaos ransomware variant copied itself to $ user \ $ appdata \ cmd . exe and launched a new process, the new process in turn created a new file in the startup folder.
We also found that in some cases, attackers used a Trojan made from a leaked builder for the Chaos ransomware to encrypt files.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
TTPs based on MITRE ATT&CK Framework: Sr No. Tactic Technique 2 Execution (TA0002) T1106: Native API T1059.003: Windows Command Shell
This, in turn, initiates several shell commands: curl ... chmod 777 ... ./7c49006c2e417f20c732409ead2d6cc0. ... rm -rf ...
Cross Site Scripting vulnerability in tiagorlampert CHAOS v.5.0.1 allows a remote attacker to escalate privileges via the sendCommandHandler function in the handler.go component.
TTPs based on MITRE ATT&CK Framework: Sr No. Tactic Technique 4 Defensive Evasion (TA0005) T1027: Obfuscated Files or Information
TTPs based on MITRE ATT&CK Framework: Sr No. Tactic Technique 1 Discovery (TA0007) T1016: System Network Configuration Discovery
TTPs based on MITRE ATT&CK Framework: Sr No. Tactic Technique 1 Discovery (TA0007) T1016: System Network Configuration Discovery T1083: File and Directory Discovery T1135: Network Share Discovery T1049: System Network Connections Discovery
Embedded C2s: quanquandd[.]top:8888 linuxddos[.]net:2323 ai.nqb001[.]com:7812 tomca1[.]com:10099 ... Staging C2s (September 2022) 154.211.21[.]221 154.19.202[.]14 ...
When the malware receives a StartProxy command from the command-and-control (C2) server, it will begin listening on an attacker-controlled TCP port and operates as a SOCKS5 proxy.
Examples include 'Chaos provides a reverse shell connection on 8338/TCP, encrypted via AES,' 'Winnti for Linux has used a custom TCP protocol with four-byte XOR for command and control,' and 'XCSSET uses RC4 encryption over TCP to communicate with its C2 server.'
Files larger than 200 MB are overwritten with random data, effectively destroying their contents.
Files of 200 MB or smaller are encrypted using AES with a randomly generated 20-character password and assigned a random four-character extension.
TTPs based on MITRE ATT&CK Framework: Sr No. Tactic Technique 6 Impact (TA0040) T1486: Data Encrypted for impact T1489: Service Stop
279 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
98 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware family used in this campaign as a destructive wiper. When run with administrator privileges, it disables recovery options, deletes shadow copies, modifies boot recovery settings, encrypts files up to 200 MB, overwrites larger files with random data, and leaves ransom notes without any payment or recovery mechanism.
Ransomware deployed as a destructive wiper rather than for extortion. It encrypts smaller files, overwrites files larger than 200 MB with random data, and, when executed with administrator rights, deletes shadow copies and disables recovery options. It targets personal folders, shared locations, saved games, and cloud-synchronized storage.
Ransomware used destructively as a wiper rather than for extortion. It encrypts smaller files, overwrites files larger than 200 MB with random data, deletes shadow copies and disables recovery options when run with administrator privileges, and leaves a note claiming data is encrypted permanently.
Chaos ransomware variant used destructively as a wiper rather than for extortion. It encrypts files of 200 MB or smaller, overwrites larger files with random data, deletes shadow-copy backups, disables Windows recovery options, and changes the desktop wallpaper.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.