Chaos is an active ransomware-as-a-service operation assessed with moderate confidence to include former BlackSuit/Royal operators from the broader Conti lineage. First observed recruiting on the RAMP forum in February 2025, the group had published 42 victims on its leak site by late March 2026 and uses triple extortion: data theft, file encryption, and threats of distributed-denial-of-service attacks. The operation is distinct from the unrelated 2021 Chaos ransomware builder.
Reported intrusions begin with spam flooding and voice phishing that pressure targets into granting Microsoft Quick Assist access. Operators then deploy legitimate remote-management tooling, steal credentials, move laterally, and exfiltrate data with GoodSync before encrypting Windows, Linux, VMware ESXi, and NAS systems. The encryptor uses Curve25519 ECDH and AES-256 with per-file keys, appends the .chaos extension, and drops README.chaos.txt; its focus on identity compromise and hypervisor/Linux environments reflects wider ransomware trends.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
By late March 2026, Chaos had named 42 victims on its leak site.
The U.S. Department of Justice seized BlackSuit infrastructure. Chaos is assessed with moderate confidence to involve former BlackSuit/Royal operators.
Chaos listed its first known victim on its leak site.
The Chaos ransomware-as-a-service operation was first observed recruiting affiliates on the RAMP forum.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 18 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
shroudcloud.io
Open sourceextrahop.com
Open sourcecyble.com
Open sourceany.run
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.