Chaos Ransomware is a ransomware family and ransomware-as-a-service operation associated with extortion activity. Public reporting indicates the malware has evolved over time, including a later C++ implementation, and has been described as using destructive extortion techniques such as deleting large files. Reported behavior also includes Bitcoin clipboard hijacking, indicating an additional cryptocurrency theft component beyond file-encryption-driven extortion. Operational reporting further characterizes Chaos Ransomware as employing double-extortion tactics, and the associated intrusion activity has been linked in some reporting to vishing-based social engineering. Separately, open-source Chaos ransomware builders have circulated publicly and have been observed bundled with other malware such as Quasar RAT, but that bundling does not by itself redefine Chaos Ransomware’s core classification as ransomware. The name has also been used in contexts involving affiliates and financially motivated targeting, including attacks against organizations in Texas. Reporting has suggested possible links between the Chaos Ransomware operation and former BlackSuit operators, although such attribution should be treated cautiously.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
The goal of the calls was to convince employees to launch a remote support session using Microsoft Quick Assist or install another remote monitoring and management tool.
Its methods of distributing malware include phishing campaigns, malicious downloads and pirated software.
In October, threat actors targeted Japanese Minecraft players with 'alt lists' allegedly containing stolen Minecraft accounts but encrypted devices with the Chaos ransomware variant instead.
After gaining remote access to employees' devices, the attackers used PowerShell to ultimately download a backdoor into the compromised user's %AppData% folder.
This activity can be significant as ".URL" files can be used as mean to trick the user into visiting certain websites unknowingly, or when placed in certain locations such as "\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\", it may allow the execution of malicious code upon system reboot.
The goal of the calls was to convince employees to launch a remote support session using Microsoft Quick Assist or install another remote monitoring and management tool.
Sophos says that when the ransomware was deployed... with at least one case where the attackers likely stole data before deploying the ransomware.
After an undisclosed amount of time, the hackers sent multiple emails to employees of the company threatening to leak stolen data if a ransom was not paid. The extortion process was clumsy but the hackers later published stolen data that the company confirmed is legitimate, according to the researchers.
The problem with Chaos ransomware variants is that they not only encrypt your data but also destroy it in many cases. While encrypting a device, any file greater than 2MB in size will be overwritten with random data and not encrypted.
This sample appears to be a Chaos Ransomware builder but it is actually bound with Quasar RAT!!
including looking for file writes (file encryption and ransomware notes), deleting shadow volume storage
The ransomware is also capable of functioning as a wiper, a dual-purpose design that has made it attractive for politically motivated or destructive campaigns; since Russia’s invasion of Ukraine, Chaos-based malware has been deployed to wipe Ukrainian systems and inflict significant damage.
56 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as related reading; no operational connection to ChaosBot is established in the content.
A ransomware family referenced as an associated analytic story.
Ransomware family described as evolving to C++ and using destructive extortion techniques, including deleting large files and hijacking the Bitcoin clipboard.
Ransomware targeting organizations in Texas, with law enforcement seizing cryptocurrency from an affiliate.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.