Chaos Ransomware: Threat Profile, Attack Chain, IOCs, and Incident Response Guide



Chaos is a ransomware-as-a-service (RaaS) operation first publicly observed in early 2025. It runs double extortion against Windows, Linux, ESXi, and NAS environments. Experts assess with moderate confidence that it is either a rebrand of BlackSuit (Royal) or is operated by former members of that group.
Three unrelated things have been called Chaos since 2021, and confusing them sends an investigation in the wrong direction on day one. This article covers the RaaS group and disambiguates the rest below.
If Chaos is active in your environment right now, incident response engagement should run in parallel with the containment steps below, not after them.
Chaos ransomware at a glance
| Attribute | Details |
|---|---|
| First observed | Early 2025 |
| Also tracked as | Chaos RaaS |
| Operating model | RaaS |
| Extortion model | Double extortion (exfiltration plus encryption) |
| Encryption | ECDH (Curve25519) key agreement with AES-256; 60-byte appendix carrying the public key in ECCPUBLICBLOB format |
| Encrypted file extension | .chaos |
| Ransom note filename | readme.chaos.txt |
| Platforms targeted | Windows, Linux, ESXi, NAS |
| Primary sectors | Technology, manufacturing, professional services, healthcare, transportation |
| Public decryptor | No |
What is Chaos ransomware?
Chaos is a human-operated RaaS in which an operator maintains the encryptor, the leak site, and the negotiation infrastructure, and affiliates run the intrusions. Through its launch and growth phase, the group advertised and recruited on RAMP (Ransom Anon Market Place), one of the few major dark web forums that openly permitted RaaS promotion after the 2021 Colonial Pipeline crackdown. That channel closed on January 28, 2026, when the FBI seized RAMP alongside the U.S. Attorney's Office for the Southern District of Florida and the DOJ's Computer Crime and Intellectual Property Section.
Reporting indicates Chaos moved public recruitment to successor marketplaces, such as Rehub, while shifting vetting and affiliate contact onto private Tox IDs and its own Tor admin panels. A decentralization that insulates the operation from the next centralized takedown.
Victim-specific Tor onion URLs remain the negotiation channel.
Extortion model
Chaos runs standard double extortion: data is exfiltrated before encryption, and publication on the leak site is the secondary leverage. Magdy Abdelaziz, Head of DFIR at Proven Data, on where destruction fits into operations like this:
"Cases where the ransomware threat actor has little or no interest in payment are uncommon. We more often see targeted wiping or deletion within a ransomware operation, especially against the recovery path. For example, an attacker may encrypt VHDX images while deleting the backup sets that could restore them. In that scenario, the goal is not pure destruction; it is control. They want the victim's viable recovery path to run through the attacker."
DO NOT PAY THE RANSOM. Decisions about ransom payment carry legal, operational, and financial consequences that qualified legal counsel and an incident response team should assess before taking any action.
Operational similarities with BlackSuit
The strongest lineage signal is structural, not circumstantial. Documentation shows that the Chaos encryptor's command-line parameters map one-to-one onto BlackSuit's:
/lkeycorresponds to BlackSuit's-idmaster key argument/encrypt_stepcorresponds to-epfor encryption percentage/kill_vmscorresponds to-stopvmfor virtual machine termination
The /encrypt_step parameter sets what percentage of each file is encrypted. Analysis observed a default of 30% and samples configured to 40%. Partial encryption is a throughput decision: it lets an affiliate render a datastore unusable far faster than full encryption, at the cost of leaving more plaintext behind. The /work_mode parameter scopes execution to the local host or the network.
Beyond execution flags, ransom note formatting and tactical approach are consistent as well. Analysis states this assessment at moderate confidence. A rebrand and a former-member spinoff are both consistent with the evidence, and public reporting has not resolved which.
For responders, the practical consequence is that BlackSuit playbooks, detections, and prior engagement notes are a reasonable starting hypothesis, not a confirmed match.
Chaos indicators of compromise
The following indicators of compromise (IOCs) allow security operations and threat hunting teams to detect, correlate, and contain active Chaos ransomware intrusions across network endpoints and infrastructure.
File and encryption indicators
| Indicator | Value |
|---|---|
| Encrypted file extension | .chaos |
| Ransom note filename | readme.chaos.txt |
| Note obfuscation | 25-byte XOR cipher |
| File appendix | 60 bytes, public key in ECCPUBLICBLOB format |
| Encryptor binaries | 32-bit Windows PE, compile timestamps February–May 2025 |
Network indicators
| Indicator | Value |
|---|---|
| C2 endpoint | 45.61.134.36:443 (reverse SSH tunnel) |
| Contact email | win88@thesecure[.]biz |
| Negotiation | Victim-specific Tor onion URLs |
| Affiliate forum presence | Rehub and private Tox IDs thereafter |
Tool-based indicators
| Category | Tools observed |
|---|---|
| Remote access/persistence | AnyDesk, ScreenConnect, OptiTune, Syncro RMM, Splashtop Streamer |
| Initial access | Microsoft Quick Assist |
| Exfiltration | GoodSync |
| Execution / lateral movement | PowerShell, WMI, cmd.exe, atexec (Impacket), mstsc.exe, SSH, SMB |
Behavioral indicators
| Behavior | Detail |
|---|---|
| Shadow copy deletion | Obfuscated cmd.exe /c vssadmin delete shadows /all |
| Encryptor invocation | /lkey:, /encrypt_step:, /work_mode:, /kill_vms parameters |
| Anti-analysis | Window and process enumeration with hash-based comparison; self-termination on detection |
| Social engineering precursor | Inbound mail flood followed within hours by a voice or Teams contact offering IT support |
Chaos branding as a false flag
In an early-2026 incident, Rapid7 assessed with moderate confidence that activity presenting as Chaos matched MuddyWater (Seedworm), an Iranian APT affiliated with the Ministry of Intelligence and Security, running an espionage operation under criminal cover.
The indicators that separated it from a genuine affiliate intrusion are worth knowing, because they are the ones a responder can check:
| Indicator | Detail |
|---|---|
| Code-signing certificate | Issued to "Donald Gay," previously tied to MuddyWater's Operation Olalampo; used to sign ms_upd.exe and Game.exe |
| C2 domain | moonzonet[.]com, linked to MuddyWater infrastructure in early 2026 |
| Execution tradecraft | pythonw.exe injecting code into suspended processes, a MuddyWater signature, not Chaos affiliate practice |
| Social engineering | Microsoft Teams approach paired with MFA manipulation |
| Behavioral tell | No file encryption occurred despite the ransomware branding |
However, a Chaos-branded incident in which nothing was actually encrypted signals that extortion may never have been the objective, and that the scoping question is what was collected and for how long rather than what was locked. Dwell time, selective collection, and targeting aligned to geopolitical rather than financial logic are the corroborating patterns.
This is one assessed incident at moderate confidence, not a characterization of the Chaos operation as a whole. The great majority of Chaos activity is financially motivated criminal extortion. But the post-RAMP fragmentation lowered the cost of wearing someone else's brand, and a leak-site listing is no longer sufficient evidence of who is on the other end.
Which Chaos variant are you dealing with?
Three distinct threats share the name. Misidentifying which one is present changes the recovery assessment entirely.
| Name | First seen | What it is | Distinguishing marks |
|---|---|---|---|
| Chaos Ransomware Builder | August 2021 | A .NET DIY builder sold on Russian-language forums; ancestry traced to Ryuk, later rebranded as Onyx and Yashma. Used by low-skill actors. | Operator-customizable extensions and notes; overwrites larger files with random bytes rather than encrypting them, making them unrecoverable |
| Chaos-C++ | 2025 | A C++ rewrite of the builder lineage. It’s the first Chaos variant not written in .NET | AES-256-CFB with an XOR fallback keyed on system tick count; mutex SvcHost_Mutex_7z459ajrk; masquerades as "System Optimizer v2.1"; files over 1.3 GB have their contents deleted outright |
| Chaos RaaS group | Early 2025 | The human-operated double-extortion operation covered in this article | .chaos extension, readme.chaos.txt note, ECDH+AES-256, leak site, Tor negotiation portal |
Important: A .chaos extension alone does not identify which threat you have. You must check the ransom note filename, whether a leak-site listing exists, and the encryptor's command line.
Who Chaos targets
Victimology is consistent with a financially opportunistic operation rather than sector-driven targeting.
| Sector | Risk profile |
|---|---|
| Technology and IT services | Highest claimed victim count. Service-provider compromise offers downstream access to client environments. |
| Manufacturing | Low tolerance for operational downtime raises payment pressure. |
| Professional services | Client confidentiality obligations amplify leak-threat leverage. |
| Healthcare | Regulated data and HIPAA exposure. |
| Transportation and logistics | Operational interdependency with customers. |
Geographically, the United States has the most claimed victims, followed by the United Kingdom, Canada, Germany, and Australia.
Disclaimer: Victim listings on ransomware leak sites represent unverified claims made by the threat actor. Treat them as unconfirmed unless corroborated by company disclosures, SEC filings, regulatory notifications, or law enforcement confirmation.
Chaos ransomware attack lifecycle
The following analysis breaks down the end-to-end execution path of modern Chaos ransomware intrusions, highlighting how threat actors leverage legitimate administrative software to bypass standard endpoint defenses.
Phase 1: Initial access
Chaos affiliates' primary entry method relies on a two-stage social engineering sequence. The affiliate first floods a target employee's inbox with high-volume spam, then calls, impersonating internal security or IT personnel, and offers to resolve the flood.
The attacker may also contact victims directly on collaboration platforms, where external accounts appear as internal helpdesk staff. The employee is directed to launch Microsoft Quick Assist, a legitimate Windows remote assistance utility, and grant the caller a session.
Affiliates also obtain entry through valid credentials sourced from brokers, infostealer logs, or exposed external remote services.
Phase 2: Execution and persistence
Once remote access is granted, the attacker installs remote monitoring and management (RMM) software to maintain persistent access after the initial support session ends.
Observed tooling includes AnyDesk, ScreenConnect, OptiTune, Syncro RMM, and Splashtop Streamer. Attackers may also establish a reverse SSH tunnel to destination IP 45.61.134.36:443 for primary command and control.
This software choice is deliberate. Because each program is signed, commercially licensed software that managed service providers legitimately deploy, endpoint detection and response (EDR) agents rarely block it. Security operations analysts are equally unlikely to escalate execution alerts without immediate access to an approved corporate software inventory.
Phase 3: Privilege escalation and discovery
Affiliates rely on native Windows living-off-the-land binaries, including PowerShell, WMI, cmd.exe, and Impacket's atexec module for remote task execution. Reconnaissance focuses on identifying Active Directory structure, network file shares, backup infrastructure, and virtualization management platforms.
Phase 4: Defense evasion
The Chaos encryptor performs anti-analysis checks prior to execution. It enumerates open windows and running processes, comparing them against hardcoded hashes to identify active debuggers, virtual machines, analysis sandboxes, and security monitoring tools.
The binary terminates immediately if it detects matching utilities. Hash-based matching ensures the malware contains no readable strings for security tools, successfully neutralizing basic string-based sample triage.
Phase 5: Lateral movement
Lateral movement across the network relies on Remote Desktop Protocol (RDP) (mstsc.exe), SSH, and SMB/WMI. While the core toolkit remains consistent across campaigns, individual affiliate tradecraft varies considerably, making lateral movement patterns an unreliable primary fingerprint.
Phase 6: Data exfiltration
Affiliates frequently exfiltrate sensitive files using GoodSync, a legitimate commercial file synchronization product. Like the choice of RMM tools, this selection minimizes detection risk: GoodSync traffic directed to cloud storage blends seamlessly with sanctioned backup operations. Because the product is benign, blocking it requires an explicit organizational policy rather than an automated EDR rule.
Phase 7: Encryption and inhibited recovery
Before launching encryption, the affiliate executes an obfuscated command (cmd.exe /c vssadmin delete shadows /all) to eliminate Volume Shadow Copies. The encryptor is subsequently executed via the command line:
Encryptor.exe /lkey:"<32-byte-key>" /encrypt_step:40 /work_mode:local_network
The cryptographic routine uses ECDH over Curve25519 for key exchange alongside AES-256 for file payload encryption. A 60-byte trailer containing the session public key formatted as an ECCPUBLICBLOB is appended to every encrypted file. Affected files are tagged with the .chaos extension, and an obfuscated ransom note (readme.chaos.txt) encrypted on disk with a 25-byte XOR cipher is generated.
The encryptor selectively skips critical system and operational areas, including the Windows, AppData, $recycle.bin, and browser directories, along with boot assets like ntuser.dat and autorun.inf. Preserving these core components keeps the host system bootable and able to load web browsers so the victim can reach the negotiation portal.
MITRE ATT&CK mapping
Mapping attack behaviors to standardized threat frameworks allows security teams to correlate observed technical telemetry with documented adversary tactics. These are Chaos ransomware observed techniques:
| Tactic | Technique | ID | Confidence |
|---|---|---|---|
| Initial Access | Spearphishing Voice | T1598.004 | Observed |
| Initial Access | Valid Accounts | T1078 | Observed |
| Initial Access | External Remote Services | T1133 | Observed |
| Execution | Windows Management Instrumentation | T1047 | Observed |
| Execution | Command and Scripting Interpreter: PowerShell | T1059.001 | Observed |
| Persistence | Remote Access Software | T1219 | Observed |
| Defense Evasion | Virtualization/Sandbox Evasion | T1497 | Observed |
| Defense Evasion | Debugger Evasion | T1622 | Observed |
| Lateral Movement | Remote Services: RDP | T1021.001 | Observed |
| Lateral Movement | Remote Services: SMB | T1021.002 | Observed |
| Exfiltration | Exfiltration Over Web Service | T1567 | Observed |
| Impact | Data Encrypted for Impact | T1486 | Observed |
| Impact | Inhibit System Recovery | T1490 | Observed |
What to do if Chaos is active in your environment
When a Chaos ransomware intrusion is actively unfolding, rapid containment and forensic preservation are critical to preventing full-network encryption and mitigating regulatory exposure.
If you suspect an active incident, contact Proven Data emergency ransomware recovery services immediately for 24/7 technical containment.
Contain at the network layer, not the power button
Sever connectivity by disabling switch ports, isolating VLANs, and shutting down the VPN concentrator. Powering hosts off destroys volatile memory that scopes the intrusion. Isolate domain controllers and backup infrastructure first.
Terminate the access path, not just the malware
Persistence can live in installed RMM software, not just a dropped file. Enumerate every remote access agent in the environment against your approved inventory, remove unapproved ones, and revoke their cloud-side sessions at the vendor console. An uninstalled agent whose account remains active is not removed.
Preserve evidence before rebuilding
Capture memory, RMM application logs, Quick Assist session records, mail gateway logs covering the flood, firewall and proxy egress records, and EDR telemetry already forwarded to the cloud console. Exfiltration scoping depends on endpoint-independent egress volume data.
Hunt persistence before restoring
Scheduled tasks, GPO modifications, and service accounts created during the intrusion survive a restore.
"Ransomware deployment often represents the final stage of a much longer intrusion. Responders must investigate both the original intrusion and the ransomware deployment; limiting analysis to the encryption event leaves the entry point unresolved and increases the risk of reinfection," explains Abdelaziz.
Rotate credentials comprehensively
Reset every domain account, reset krbtgt twice, and revoke OAuth grants, API keys, and active sessions. Resets without revocation leave live sessions running.
Assess regulatory exposure immediately
Exfiltration precedes encryption in this operation, so notification clocks may already be running. Counsel needs to determine which apply before they expire.
Does Chaos ransomware have a public decryptor?
No public decryptor exists for the Chaos RaaS group's encryptor. The implementation uses ECDH over Curve25519 to derive a per-victim key with AES-256 for file data, and the public key written into each file's 60-byte appendix provides no path to the private key. No cryptographic flaw has been publicly reported. Check No More Ransom before concluding, as the landscape changes.
Detection, threat hunting, and defensive hardening
The highest-signal observable for Chaos is not a file hash. It is the sequence of an inbound mail flood followed by an unscheduled remote assistance session within the same business day. That pairing is nearly unique to this intrusion pattern and detectable without malware.
The following consolidated checklist aligns instrumentation priorities with core defensive controls.
Neutralize initial access vectors
- Quick Assist Controls: Restrict or alert on quickassist.exe execution. Any session starting without a corresponding helpdesk ticket warrants immediate triage; block the executable outright where no valid business case exists.
- Mail Flood Correlation: Correlate email gateway volume spikes with endpoint behavior. An employee receiving hundreds of messages in minutes should automatically raise that user endpoint's EDR alerting sensitivity for 24 hours.
- Out-of-Band Verification: Enforce out-of-band identity verification procedures for staff following a mail flood, ensuring employees do not rely on communication channels initiated by the caller.
- External Messaging Restrictions: Restrict external Microsoft Teams tenants from initiating direct contact with internal employees to block secondary social engineering pathways.
Detect and restrict unauthorized tooling
- RMM Software Inventory: Keep an explicitly approved inventory of remote access software (e.g., AnyDesk, ScreenConnect). Alert immediately on deviations, as unapproved RMM installations are a primary persistence vector.
- Exfiltration Monitoring: Monitor for file synchronization clients (such as GoodSync) creating outbound sessions from server infrastructure rather than standard user workstations.
Harden infrastructure and recovery paths
- Shadow Copy Protection: Set high-severity alerts on shadow copy deletion commands (vssadmin delete shadows) regardless of the parent process. This execution is the final reliable warning before encryption begins.
- Backup Segmentation: Isolate backup infrastructure on dedicated network segments using credentials that do not authenticate against the primary Active Directory domain. Anything reachable from a compromised domain account will be targeted prior to payload execution.
- Multi-Platform EDR Coverage: Deploy endpoint protection across ESXi hypervisors and Linux environments. Restricting monitoring tools to Windows hosts leaves cross-platform targets unmonitored.
- Strict Authentication Controls: Enforce Multi-Factor Authentication (MFA) across every remote access path and administrative portal to block access via valid credentials.

Written by
Cybersecurity writer at Proven Data covering ransomware trends, incident response, and data protection best practices.

Written by
Magdy Abdelaziz is a dedicated cybersecurity professional with over 7 years of extensive experience in digital forensics, incident response, reverse engineering, and security operations. He currently serves as Head of Digital Forensics and Incident Response (DFIR) at Proven Data LLC, leading a multinational team to develop and execute incident response strategies, align security initiatives with business objectives, and manage global-scale incidents.

Reviewed by
Content strategist at Proven Data focused on cybersecurity education, threat analysis, and ransomware awareness.





