Chaos is a ransomware-as-a-service operation active since at least February 2025 and associated with financially motivated intrusions and double-extortion activity. The group has been linked to operators or affiliates connected to the broader post-Royal and BlackSuit ransomware ecosystem. Chaos targets organizations across multiple sectors and geographies, with observed victimization in North America, Europe, Russia, and Singapore. Chaos operators have used voice phishing and spam email for initial access, including campaigns in which attackers impersonated IT support staff over Microsoft Teams to persuade employees to launch remote-support sessions through legitimate tools such as Quick Assist or other remote administration software. After access is obtained, the group conducts reconnaissance, profiles hosts, identifies security products, establishes persistence, enables secondary remote-access channels, and attempts lateral movement including Remote Desktop Protocol enablement. Persistence has been disguised as benign system or audio-related components, and operators have repeatedly changed filenames, deployment methods, and persistence mechanisms to evade detection. The group has also used legitimate remote monitoring and management tools and reverse proxying to maintain access inside victim environments. Data theft has been observed prior to ransomware deployment, and public leak pressure has been used against victims, including staged publication of samples and deadlines for negotiation. This supports a mature double-extortion model combining encryption with exfiltration-based coercion. Chaos maintains a leak-site presence and has appeared in public ransomware claim reporting as an active extortion actor. A notable Chaos-associated malware family is msaRAT, a Rust-based remote access trojan used post-compromise before encryption. msaRAT avoids making direct outbound connections from the malware process and instead launches Chrome or Microsoft Edge in headless mode, controls the browser through the Chrome DevTools Protocol, and establishes command-and-control over a WebRTC data channel. Signaling is performed through Cloudflare Workers and relay infrastructure is forced through TURN services, causing malicious traffic to blend into ordinary browser activity. The malware supports remote command execution, covert tunneling, and layered encryption, and reflects a strong emphasis on defense evasion and stealthy post-exploitation. Known aliases include Chaos ransomware, Chaos ransomware group, Chaos ransomware operators, Chaos ransomware affiliates, and Chaos ransomware-as-a-service operation. This actor is distinct from the older Chaos ransomware family first seen in 2021.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware-as-a-service operation used in the intrusions tied to STAC4749; ransom notes claimed data theft and threatened leaks if payment was not made.
Ransomware-as-a-service operation used in at least three known STAC4749 compromises to encrypt victim endpoints.
Named as the ransomware group responsible for the attack and data breach affecting Craneware.
Conducting a ransomware/data extortion attack against vit-best.com and claiming to have breached the victim's infrastructure, exfiltrated critical data, and begun publishing stolen data with a countdown to release the remainder.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.