A ransomware strain dubbed WannaFriendMe was found directing victims to buy a Roblox Game Pass named "Ryuk Decrypter" with Robux and then email proof of purchase to an iCloud address to obtain a decryptor. Researchers and reporting tied the malware not to Ryuk, despite its branding, but to the Chaos ransomware family, a .NET builder-based strain that lets operators customize ransom notes, file extensions, and other behaviors. Roblox said the incident did not involve a platform vulnerability, and the company removed the Game Pass and permanently banned the account behind it.
The case highlighted the real-world abuse potential of the Chaos builder, which security researchers had previously tracked as an evolving proof of concept with destructive behavior closer to a wiper than conventional ransomware. Trend Micro and Qualys reported that successive Chaos versions added privilege escalation, shadow-copy deletion, recovery disabling, wallpaper changes, and AES/RSA encryption for smaller files, while files larger than roughly 2 MB were overwritten with random data and often rendered unrecoverable. That design means victims may lose data even if a decryptor is provided, making WannaFriendMe notable both for its unusual Roblox-based payment scheme and for the severe data-destruction risks inherited from Chaos.

TTPs, infrastructure, and targeting history in one profile.
11 events from the most recent confirmed update back to the earliest known activity.
On January 17, 2022, Qualys published analysis of the latest observed Chaos version and assessed that it behaved more like a wiper than traditional ransomware. The report detailed its encryption of files smaller than about 2 MB and destructive overwriting of larger files.
On August 10, 2021, Trend Micro published research on Chaos, documenting its rapid evolution across four versions and warning that it could become dangerous if paired with effective malware deployment infrastructure. The researchers said they had not observed active infections or victims at that time.
Chaos version 4.0 was released on August 5, 2021. It raised the encryption limit to about 2 MB and added customizable file extensions and wallpaper changes.
Chaos version 3.0 was released on July 5, 2021. It added AES/RSA encryption for files under 1 MB and included a decrypter builder, marking a shift toward more typical ransomware behavior.
Chaos version 2.0 was released on June 17, 2021. It added options for administrator privileges and capabilities to delete shadow copies, backup catalogs, and disable Windows recovery mode.
Chaos version 1.0 was released on June 9, 2021. This early version overwrote targeted files with random bytes and Base64-encoded them, behaving more like a destructive wiper than conventional ransomware.
Researchers began monitoring the in-development Chaos ransomware builder in June 2021 after it was offered for testing on an underground forum. It was advertised as a .NET version of Ryuk despite sharing little with the Ryuk family.
Roblox said the incident did not involve any exploit or vulnerability on its platform. The company removed the Game Pass associated with the ransomware decryptor and permanently removed the responsible account for violating its Terms of Service.
Security researcher MalwareHunterTeam found a new ransomware strain named WannaFriendMe. The malware impersonated Ryuk but was actually a Chaos ransomware variant that instructed victims to buy a Roblox Game Pass as payment for a decryptor.
A Roblox Game Pass named 'Ryuk Decrypter' tied to the WannaFriendMe ransom scheme had last been updated on June 5th. The listing was sold by a user named 'iRazormind' for 1,499 Robux.
In October, threat actors targeted Japanese Minecraft players with purported 'alt lists' containing stolen accounts that instead deployed a Chaos ransomware variant. This was cited as a prior example of Chaos variants being used against gamers.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourceblog.qualys.com
Open sourcetrendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.