Chaos ransomware has undergone a significant transformation in 2025, resurfacing with a new variant written in C++ rather than its previous .NET implementation. This marks a notable shift in the malware's development, indicating a move toward more sophisticated and potentially evasive techniques. The new Chaos-C++ variant targets Microsoft Windows systems and is capable of encrypting most files on compromised machines, resulting in a high-severity impact for affected users. In addition to traditional file encryption and ransom demands, the updated ransomware introduces destructive extortion tactics, increasing the pressure on victims to comply with attackers' demands. A particularly concerning feature of this variant is its clipboard hijacking mechanism, which is designed to steal cryptocurrency by monitoring and replacing clipboard contents related to wallet addresses. The ransomware is distributed via a downloader that masquerades as a legitimate utility called 'System Optimizer v2.1,' deceiving users with fake optimization messages while covertly deploying the malicious payload. During execution, the downloader creates a hidden log file, 'sysopt.log,' in the %TMP% directory to record details of the payload's download and execution. The actual ransomware payload is written to a temporary file with a randomized name, further complicating detection and analysis. The downloader uses hardcoded strings and attempts to launch the payload using the CreateProcessA() function with specific flags to avoid user detection. Technical analysis reveals that the C++ implementation allows for more efficient and potentially faster execution, as well as the integration of new features not present in earlier .NET-based versions. The evolution of Chaos ransomware reflects a broader trend of ransomware operators adopting more aggressive and financially motivated tactics, including data destruction and cryptocurrency theft. Security researchers emphasize the importance of understanding these new attacker tactics to assess organizational exposure and prioritize defensive measures. The shift to C++ may also indicate an attempt to evade signature-based detection tools that were tuned for the .NET variant. Organizations are urged to remain vigilant, update their security controls, and educate users about the risks of downloading and running suspicious utilities. The technical details provided in the analysis offer valuable insights for defenders seeking to detect and mitigate this evolving threat. The emergence of clipboard hijacking as part of the ransomware's toolkit highlights the increasing convergence of ransomware and information-stealing malware. This development underscores the need for comprehensive endpoint protection and user awareness training to counteract sophisticated social engineering and technical evasion techniques. The Chaos-C++ variant's operational changes and enhanced capabilities represent a significant escalation in the threat landscape for Windows users worldwide.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
Analysis published by Fortinet described Chaos-C++ using size-based file handling to encrypt smaller files, skip mid-sized files, and delete the contents of files larger than 1.3 GB, while also adding clipboard hijacking to replace copied Bitcoin addresses with an attacker-controlled wallet. The report also noted recovery-inhibiting commands, AES-256-CFB encryption via CryptoAPI with an XOR fallback, and warned the family may be evolving toward wiper-like behavior.
FortiGuard Labs reported that the Chaos ransomware family re-emerged in 2025 with a new Windows-targeting variant dubbed "Chaos-C++," assessed as the first version of the family not written in .NET. The campaign used a downloader disguised as "System Optimizer v2.1" to deploy the ransomware payload.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
6 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcehackread.com
Open sourcesecurityonline.info
Open sourcedarkreading.com
Open sourcefortinet.com
Open sourcefeeds.fortinet.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.