Chaos refers to multiple distinct malware/ransomware families in the provided content. The name is most prominently used for: (1) a ransomware builder/ransomware family first monitored from June 2021 and described as ransomware-as-a-service, whose builder enabled low-skill actors to generate customized campaigns; variants were distributed via phishing, malicious downloads, and pirated software, targeted schools, small businesses, local governments, and individuals, and in some cases copied themselves to %AppData% as cmd.exe and created startup-folder persistence via cmd.url. Content also states Chaos-based malware has been used as a wiper and that leaked Chaos builder-derived samples were used by actors such as Key Group and Twelve; Onyx ransomware is described as based on Chaos. (2) a separate ransomware-as-a-service operation active since February 2025, assessed with moderate confidence as involving former BlackSuit/Royal operators. This 2025 Chaos operation uses an open affiliate model, recruits on RAMP, and conducts double/triple extortion through data theft, encryption, leak-site pressure, and reported DDoS threats. It targets organizations opportunistically, with a big-game-hunting posture, mostly in the United States, with technology and financial services specifically mentioned. Reported tradecraft includes spam flooding and voice phishing to induce Microsoft Quick Assist sessions, use of compromised RDP credentials and unpatched edge-device exploitation, deployment of AnyDesk, ScreenConnect, OptiTune, Syncro RMM, and Splashtop Streamer, reverse SSH tunnels over port 443, reconnaissance of domain controllers and trusts, Mimikatz, Kerberoasting, bulk password resets with net.exe, token impersonation, lateral movement via RDP and Impacket, and exfiltration with GoodSync renamed to wininit.exe. Its encryptor supports Windows, Linux, ESXi, and NAS, uses Curve25519 ECDH and AES-256 with per-file unique keys, appends the .chaos extension, and drops README.chaos.txt/readme.chaos.txt ransom notes. The content also notes false-flag incidents in early 2026 where MuddyWater/MOIS-linked actors used Chaos branding and leak-site theatrics without deploying encryption. (3) a distinct Go-based cross-platform malware/botnet first documented by Lumen Black Lotus Labs in September 2022, historically targeting routers and edge devices and assessed as likely an evolution of Kaiji. This Chaos malware can execute remote shell commands, deploy additional modules, propagate via SSH brute-forcing, mine cryptocurrency, and launch DDoS attacks over HTTP, TLS, TCP, UDP, and WebSocket. Newer 2026 Linux ELF variants targeted misconfigured Hadoop/cloud deployments by creating malicious applications that downloaded and executed a Chaos binary from pan.tenire[.]com, then deleted it from disk. Reported additions include systemd persistence, keep-alive scripts, SOCKS/SOCKS5 proxy capability, and C2 infrastructure such as gmserver.osfc[.]org[.]cn over port 65111; Darktrace also cited attacker IP 182[.]90.229.95 and sample hash ae457fc5e07195509f074fe45a6521e7fd9e4cd3cd43e42d10b0222b34f2de7a. The content notes suspected but unconfirmed Chinese origin for this botnet based on language and infrastructure artifacts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
While the Chaos ransomware variant copied itself to $ user \ $ appdata \ cmd . exe and launched a new process, the new process in turn created a new file in the startup folder.
We also found that in some cases, attackers used a Trojan made from a leaked builder for the Chaos ransomware to encrypt files.
The CyberVolk collective is a prime example of how readily threat actors can access and deploy dangerous ransomware builders such as AzzaSec, Diamond, LockBit, Chaos and others.
Nation-state hackers from Iran are deploying the Chaos ransomware as cover for alleged espionage and data theft operations... The Chaos ransomware operation has existed since February 2025...
A newly emerged ransomware-as-a-service (RaaS) gang called Chaos is likely made up of former members of the BlackSuit crew... Chaos, which sprang forth in February 2025...
A newly emerged ransomware-as-a-service (RaaS) gang called Chaos is likely made up of former members of the BlackSuit crew... Chaos, which sprang forth in February 2025...
31 distinct techniques documented for this family, organized by ATT&CK tactic.
One of the more interesting functions of Chaos version 1.0 was its worming function, which allowed it to spread to all drives found on an affected system. This could permit the malware to jump onto removable drives and escape from air-gapped systems.
Darktrace said it identified the new variant targeting its honeypot network last month, a deliberately misconfigured Hadoop instance that enables remote code execution on the service. In the attack spotted by the cybersecurity company, the intrusion commenced with an HTTP request to the Hadoop deployment to create a new application.
the adversary used Scheduler tasks set up by modifying group policies. This enabled the adversary to execute these on all machines in the domain at the same time
Chaos is a cross-platform malware that can run remote shell commands...
The application, for its part, embedded a sequence of shell commands to retrieve a Chaos agent binary from an attacker-controlled server ('pan.tenire[.]com'), set permissions to allow all users to read, modify, or run it ('chmod 777'), and then actually execute the binary and delete the artifact from disk to minimize the forensic trail.
the adversary used Scheduler tasks set up by modifying group policies. This enabled the adversary to execute these on all machines in the domain at the same time
For example, the persistence mechanism was always via the registry, but the exact implementation differed by family. Most of the time, autorun was used, but we’ve also seen them using the startup folder.
While the Chaos ransomware variant copied itself to $ user \ $ appdata \ cmd . exe and launched a new process, the new process in turn created a new file in the startup folder: $ user \ $ appdata \ Microsoft \ Windows \ Start Menu \ Programs \ Startup \ cmd . url . This contained the path to the ransomware file
the adversary used Scheduler tasks set up by modifying group policies. This enabled the adversary to execute these on all machines in the domain at the same time
they tried distributing and running malware through the task scheduler and modified group policies to save malicious tasks for the entire domain
For example, the persistence mechanism was always via the registry, but the exact implementation differed by family. Most of the time, autorun was used, but we’ve also seen them using the startup folder.
While the Chaos ransomware variant copied itself to $ user \ $ appdata \ cmd . exe and launched a new process, the new process in turn created a new file in the startup folder: $ user \ $ appdata \ Microsoft \ Windows \ Start Menu \ Programs \ Startup \ cmd . url . This contained the path to the ransomware file
It also has the kind of tradecraft defenders should not shrug off: social engineering, remote-management abuse, payload retrieval, staging, and leaked data.
The command-and-control server is reached through an embedded domain, gmserver[.]osfc[.]org[.]cn, which at the time of analysis resolved to an IP address geolocated to Hong Kong.
The new 64-bit ELF binary has removed SSH propagation and router exploit functions, replacing them with a SOCKS proxy feature to ferry traffic and conceal malicious activity.
When the malware receives a StartProxy command from the command-and-control (C2) server, it will begin listening on an attacker-controlled TCP port and operates as a SOCKS5 proxy.
Smyth Companies, LLC has failed to protect its infrastructure. We have successfully exfiltrated high...
Instead of encrypting files (which could then be decrypted after the target paid the ransom), it replaced the files’ contents with random bytes, after which the files were encoded in Base64. This meant that affected files could no longer be restored
aphenapharma.com — an organization based in US — has fallen victim to a ransomware attack conducted by the group chaos.
The second version of Chaos added advanced options for administrator privileges, the ability to delete all volume shadow copies and the backup catalog, and the ability to disable Windows recovery mode.
In addition, it gives the ransomware builder’s users the ability to add their own extensions to affected files and the ability to change the desktop wallpaper of their victims.
89 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
51 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Chaos is a ransomware-as-a-service family whose builder enables low-skill actors to create customized ransomware campaigns. The content says it is distributed via phishing, malicious downloads, and pirated software, and that it can also function as a wiper, making it useful for destructive as well as extortion-driven operations.
Ransomware derived from a leaked builder and used in some incidents to encrypt files; static analysis linked samples to the Twelve group.
A ransomware variant used by Key Group that copied itself into AppData, launched a new process, and created a startup-folder URL file for persistence.
Chaos is a ransomware-as-a-service operation associated with double-extortion attacks involving data exfiltration and file encryption. In the reported intrusion, its branding and artifacts were used as a false flag, but no encryption occurred.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.