Chaos is a ransomware-as-a-service operation active since at least early 2025 and publicly observed from March 2025. It is associated with double-extortion activity, a dedicated leak site, and affiliate-style operations that have targeted organizations in multiple countries. Reported victims span health care, technology, professional services, transportation and logistics, retail-related distribution, and education, with activity also appearing in broader industrial ransomware reporting. Chaos operators have been linked to initial access through spam email and voice-based social engineering, including Microsoft Teams and vishing lures in which attackers impersonate IT support staff and persuade users to grant remote access through legitimate support tools. Intrusions attributed to the Chaos ecosystem have used Quick Assist, RemSupp, AnyDesk, DWAgent, and other remote-management tooling, followed by PowerShell-delivered malware, persistence mechanisms disguised as legitimate software components, reconnaissance, attempted RDP enablement, secondary remote-access channels, and reverse SOCKS-style proxying for internal access and lateral movement. The group has also been tied to msaRAT, a Rust-based remote access trojan used before ransomware deployment. msaRAT is notable for delegating external command-and-control traffic to the victim’s Chrome or Edge browser via the Chrome DevTools Protocol, using headless browser sessions, WebRTC data channels, and relay infrastructure to blend malicious communications into normal browser activity. This reflects a strong emphasis on defense evasion and post-compromise operational flexibility. Chaos conducts extortion through both encryption and theft of sensitive data, with leak-site postings and countdown-based pressure tactics used to coerce victims. At least some intrusions associated with Chaos involved data theft prior to encryption. Reporting also indicates that activity branded as Chaos diverged into distinct operations during 2026, and the brand has been abused as cover in at least one state-aligned false-flag espionage operation by MuddyWater. Separate reporting links Chaos to former members of the BlackSuit and Royal ransomware ecosystems. Desorden has described itself as formed by former associates of Chaos, but its current relationship to Chaos is not established with high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only in post navigation as a separate article topic.
Referenced as a separate ransomware group associated with msaRAT, using a headless browser controlled via CDP and Twilio TURN relays for covert communications, and noted for Teams voice phishing campaigns to deploy ransomware.
Ransomware-as-a-Service group operating a dedicated leak site and claiming a data theft/extortion incident involving Healthcare Highways, including an alleged dump of 235 GB of PHI and internal documents.
Chaos branding covered both a conventional financially motivated RaaS operation and a separate state-sponsored espionage campaign, illustrating how ransomware branding can be used as cover and complicate attribution.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.