A new Rust-based backdoor known as ChaosBot has been identified targeting financial services organizations, with researchers first detecting the malware in late September 2025. ChaosBot is notable for its use of Discord channels as a covert command-and-control (C2) mechanism, allowing threat actors to issue remote commands and maintain persistent access to compromised systems. The malware campaign was discovered after attackers leveraged compromised credentials, including those mapped to Cisco VPN and an over-privileged Active Directory account, to gain initial access to a financial services network. Once inside, the attackers used Windows Management Instrumentation (WMI) to execute remote commands and deploy ChaosBot across multiple systems. Distribution of ChaosBot has also been observed via phishing emails containing malicious Windows shortcut (LNK) files, which, when opened, execute a PowerShell command to download and run the malware. To distract victims, the phishing campaign displays a decoy PDF purporting to be legitimate correspondence from the State Bank of Vietnam. The core payload is a malicious DLL named 'msedge_elf.dll', which is sideloaded using the Microsoft Edge binary 'identity_helper.exe' to evade detection. Upon execution, ChaosBot performs system reconnaissance and downloads a fast reverse proxy (FRP) tool to establish a reverse proxy, facilitating ongoing access to the victim network. The threat actors behind ChaosBot, operating under the Discord handle 'chaos_00019', have also attempted to configure Visual Studio Code Tunnel services as an additional backdoor, though these efforts were reportedly unsuccessful. The campaign demonstrates a sophisticated approach to persistence and lateral movement, combining credential abuse, living-off-the-land techniques, and novel C2 infrastructure. Security researchers have highlighted the risk posed by the abuse of legitimate collaboration platforms like Discord for malware control, which can bypass traditional network defenses. The use of Rust as the malware's programming language further complicates detection and analysis due to its cross-platform capabilities and relative novelty in the malware ecosystem. Financial services organizations are urged to review credential hygiene, monitor for unusual VPN and Active Directory activity, and scrutinize the use of Discord and other messaging platforms within their environments. The campaign underscores the ongoing evolution of malware delivery and C2 tactics, particularly in targeting high-value sectors such as finance.

See the actors and campaigns active against you right now.
4 events from the most recent confirmed update back to the earliest known activity.
Separate reporting described a C++-based Chaos ransomware variant called Chaos-C++ that adds destructive behavior by deleting contents of very large files instead of encrypting them and includes clipboard hijacking to swap Bitcoin addresses. Researchers also noted its fake-utility downloader, execution marker file, and recovery-inhibition behavior when run with administrator privileges.
Researchers published technical details on ChaosBot, including its DLL sideloading chain using msedge_elf.dll and identity_helper.exe, phishing delivery via malicious LNK files, FRP persistence, attempted VS Code Tunnel use, and newer variants with ETW bypass and VM evasion. The disclosure identified the malware as targeting financial services environments.
During the intrusion, the threat actor used WMI for remote command execution to deploy ChaosBot on Windows systems. The malware established command-and-control through Discord by creating victim-specific channels and supporting shell commands, screenshots, and file transfer.
eSentire reported detecting a new Rust-based backdoor dubbed ChaosBot in late September 2025 during an intrusion affecting a financial services organization. The attackers used compromised Cisco VPN credentials and an over-privileged Active Directory account to gain and expand access.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
3 references tracked. Mallory keeps watching after this page renders.
osintteam.blog
Open sourcesecurityonline.info
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.