Chaos Ransomware: Threat Profile, Attack Chain, IOCs, and Incident Response Guide

Heloise Montini
Heloise Montini
&
Magdy Abdelaziz
Magdy Abdelaziz
·Published:
Chaos Ransomware: Threat Profile, Attack Chain, IOCs, and Incident Response Guide

Chaos is a ransomware-as-a-service (RaaS) operation first publicly observed in early 2025. It runs double extortion against Windows, Linux, ESXi, and NAS environments. Experts assess with moderate confidence that it is either a rebrand of BlackSuit (Royal) or is operated by former members of that group.

Three unrelated things have been called Chaos since 2021, and confusing them sends an investigation in the wrong direction on day one. This article covers the RaaS group and disambiguates the rest below.

If Chaos is active in your environment right now, incident response engagement should run in parallel with the containment steps below, not after them.

Chaos ransomware at a glance

AttributeDetails
First observedEarly 2025
Also tracked asChaos RaaS
Operating modelRaaS
Extortion modelDouble extortion (exfiltration plus encryption)
EncryptionECDH (Curve25519) key agreement with AES-256; 60-byte appendix carrying the public key in ECCPUBLICBLOB format
Encrypted file extension.chaos
Ransom note filenamereadme.chaos.txt
Platforms targetedWindows, Linux, ESXi, NAS
Primary sectorsTechnology, manufacturing, professional services, healthcare, transportation
Public decryptorNo

What is Chaos ransomware?

Chaos is a human-operated RaaS in which an operator maintains the encryptor, the leak site, and the negotiation infrastructure, and affiliates run the intrusions. Through its launch and growth phase, the group advertised and recruited on RAMP (Ransom Anon Market Place), one of the few major dark web forums that openly permitted RaaS promotion after the 2021 Colonial Pipeline crackdown. That channel closed on January 28, 2026, when the FBI seized RAMP alongside the U.S. Attorney's Office for the Southern District of Florida and the DOJ's Computer Crime and Intellectual Property Section.

Reporting indicates Chaos moved public recruitment to successor marketplaces, such as Rehub, while shifting vetting and affiliate contact onto private Tox IDs and its own Tor admin panels. A decentralization that insulates the operation from the next centralized takedown.

Victim-specific Tor onion URLs remain the negotiation channel.

Extortion model

Chaos runs standard double extortion: data is exfiltrated before encryption, and publication on the leak site is the secondary leverage. Magdy Abdelaziz, Head of DFIR at Proven Data, on where destruction fits into operations like this:

"Cases where the ransomware threat actor has little or no interest in payment are uncommon. We more often see targeted wiping or deletion within a ransomware operation, especially against the recovery path. For example, an attacker may encrypt VHDX images while deleting the backup sets that could restore them. In that scenario, the goal is not pure destruction; it is control. They want the victim's viable recovery path to run through the attacker."

DO NOT PAY THE RANSOM. Decisions about ransom payment carry legal, operational, and financial consequences that qualified legal counsel and an incident response team should assess before taking any action.

Operational similarities with BlackSuit

The strongest lineage signal is structural, not circumstantial. Documentation shows that the Chaos encryptor's command-line parameters map one-to-one onto BlackSuit's:

  • /lkey corresponds to BlackSuit's -id master key argument
  • /encrypt_step corresponds to -ep for encryption percentage
  • /kill_vms corresponds to -stopvm for virtual machine termination

The /encrypt_step parameter sets what percentage of each file is encrypted. Analysis observed a default of 30% and samples configured to 40%. Partial encryption is a throughput decision: it lets an affiliate render a datastore unusable far faster than full encryption, at the cost of leaving more plaintext behind. The /work_mode parameter scopes execution to the local host or the network.

Beyond execution flags, ransom note formatting and tactical approach are consistent as well. Analysis states this assessment at moderate confidence. A rebrand and a former-member spinoff are both consistent with the evidence, and public reporting has not resolved which.

For responders, the practical consequence is that BlackSuit playbooks, detections, and prior engagement notes are a reasonable starting hypothesis, not a confirmed match.

Chaos indicators of compromise

The following indicators of compromise (IOCs) allow security operations and threat hunting teams to detect, correlate, and contain active Chaos ransomware intrusions across network endpoints and infrastructure.

File and encryption indicators

IndicatorValue
Encrypted file extension.chaos
Ransom note filenamereadme.chaos.txt
Note obfuscation25-byte XOR cipher
File appendix60 bytes, public key in ECCPUBLICBLOB format
Encryptor binaries32-bit Windows PE, compile timestamps February–May 2025

Network indicators

IndicatorValue
C2 endpoint45.61.134.36:443 (reverse SSH tunnel)
Contact emailwin88@thesecure[.]biz
NegotiationVictim-specific Tor onion URLs
Affiliate forum presenceRehub and private Tox IDs thereafter

Tool-based indicators

CategoryTools observed
Remote access/persistenceAnyDesk, ScreenConnect, OptiTune, Syncro RMM, Splashtop Streamer
Initial accessMicrosoft Quick Assist
ExfiltrationGoodSync
Execution / lateral movementPowerShell, WMI, cmd.exe, atexec (Impacket), mstsc.exe, SSH, SMB

Behavioral indicators

BehaviorDetail
Shadow copy deletionObfuscated cmd.exe /c vssadmin delete shadows /all
Encryptor invocation/lkey:, /encrypt_step:, /work_mode:, /kill_vms parameters
Anti-analysisWindow and process enumeration with hash-based comparison; self-termination on detection
Social engineering precursorInbound mail flood followed within hours by a voice or Teams contact offering IT support

Chaos branding as a false flag

In an early-2026 incident, Rapid7 assessed with moderate confidence that activity presenting as Chaos matched MuddyWater (Seedworm), an Iranian APT affiliated with the Ministry of Intelligence and Security, running an espionage operation under criminal cover.

The indicators that separated it from a genuine affiliate intrusion are worth knowing, because they are the ones a responder can check:

IndicatorDetail
Code-signing certificateIssued to "Donald Gay," previously tied to MuddyWater's Operation Olalampo; used to sign ms_upd.exe and Game.exe
C2 domainmoonzonet[.]com, linked to MuddyWater infrastructure in early 2026
Execution tradecraftpythonw.exe injecting code into suspended processes, a MuddyWater signature, not Chaos affiliate practice
Social engineeringMicrosoft Teams approach paired with MFA manipulation
Behavioral tellNo file encryption occurred despite the ransomware branding

However, a Chaos-branded incident in which nothing was actually encrypted signals that extortion may never have been the objective, and that the scoping question is what was collected and for how long rather than what was locked. Dwell time, selective collection, and targeting aligned to geopolitical rather than financial logic are the corroborating patterns.

This is one assessed incident at moderate confidence, not a characterization of the Chaos operation as a whole. The great majority of Chaos activity is financially motivated criminal extortion. But the post-RAMP fragmentation lowered the cost of wearing someone else's brand, and a leak-site listing is no longer sufficient evidence of who is on the other end.

Which Chaos variant are you dealing with?

Three distinct threats share the name. Misidentifying which one is present changes the recovery assessment entirely.

NameFirst seenWhat it isDistinguishing marks
Chaos Ransomware BuilderAugust 2021A .NET DIY builder sold on Russian-language forums; ancestry traced to Ryuk, later rebranded as Onyx and Yashma. Used by low-skill actors.Operator-customizable extensions and notes; overwrites larger files with random bytes rather than encrypting them, making them unrecoverable
Chaos-C++2025A C++ rewrite of the builder lineage. It’s the first Chaos variant not written in .NETAES-256-CFB with an XOR fallback keyed on system tick count; mutex SvcHost_Mutex_7z459ajrk; masquerades as "System Optimizer v2.1"; files over 1.3 GB have their contents deleted outright
Chaos RaaS groupEarly 2025The human-operated double-extortion operation covered in this article.chaos extension, readme.chaos.txt note, ECDH+AES-256, leak site, Tor negotiation portal

Important: A .chaos extension alone does not identify which threat you have. You must check the ransom note filename, whether a leak-site listing exists, and the encryptor's command line.

Who Chaos targets

Victimology is consistent with a financially opportunistic operation rather than sector-driven targeting.

SectorRisk profile
Technology and IT servicesHighest claimed victim count. Service-provider compromise offers downstream access to client environments.
ManufacturingLow tolerance for operational downtime raises payment pressure.
Professional servicesClient confidentiality obligations amplify leak-threat leverage.
HealthcareRegulated data and HIPAA exposure.
Transportation and logisticsOperational interdependency with customers.

Geographically, the United States has the most claimed victims, followed by the United Kingdom, Canada, Germany, and Australia.

Disclaimer: Victim listings on ransomware leak sites represent unverified claims made by the threat actor. Treat them as unconfirmed unless corroborated by company disclosures, SEC filings, regulatory notifications, or law enforcement confirmation.

Chaos ransomware attack lifecycle

The following analysis breaks down the end-to-end execution path of modern Chaos ransomware intrusions, highlighting how threat actors leverage legitimate administrative software to bypass standard endpoint defenses.

Phase 1: Initial access

Chaos affiliates' primary entry method relies on a two-stage social engineering sequence. The affiliate first floods a target employee's inbox with high-volume spam, then calls, impersonating internal security or IT personnel, and offers to resolve the flood.

The attacker may also contact victims directly on collaboration platforms, where external accounts appear as internal helpdesk staff. The employee is directed to launch Microsoft Quick Assist, a legitimate Windows remote assistance utility, and grant the caller a session.

Affiliates also obtain entry through valid credentials sourced from brokers, infostealer logs, or exposed external remote services.

Phase 2: Execution and persistence

Once remote access is granted, the attacker installs remote monitoring and management (RMM) software to maintain persistent access after the initial support session ends.

Observed tooling includes AnyDesk, ScreenConnect, OptiTune, Syncro RMM, and Splashtop Streamer. Attackers may also establish a reverse SSH tunnel to destination IP 45.61.134.36:443 for primary command and control.

This software choice is deliberate. Because each program is signed, commercially licensed software that managed service providers legitimately deploy, endpoint detection and response (EDR) agents rarely block it. Security operations analysts are equally unlikely to escalate execution alerts without immediate access to an approved corporate software inventory.

Phase 3: Privilege escalation and discovery

Affiliates rely on native Windows living-off-the-land binaries, including PowerShell, WMI, cmd.exe, and Impacket's atexec module for remote task execution. Reconnaissance focuses on identifying Active Directory structure, network file shares, backup infrastructure, and virtualization management platforms.

Phase 4: Defense evasion

The Chaos encryptor performs anti-analysis checks prior to execution. It enumerates open windows and running processes, comparing them against hardcoded hashes to identify active debuggers, virtual machines, analysis sandboxes, and security monitoring tools.

The binary terminates immediately if it detects matching utilities. Hash-based matching ensures the malware contains no readable strings for security tools, successfully neutralizing basic string-based sample triage.

Phase 5: Lateral movement

Lateral movement across the network relies on Remote Desktop Protocol (RDP) (mstsc.exe), SSH, and SMB/WMI. While the core toolkit remains consistent across campaigns, individual affiliate tradecraft varies considerably, making lateral movement patterns an unreliable primary fingerprint.

Phase 6: Data exfiltration

Affiliates frequently exfiltrate sensitive files using GoodSync, a legitimate commercial file synchronization product. Like the choice of RMM tools, this selection minimizes detection risk: GoodSync traffic directed to cloud storage blends seamlessly with sanctioned backup operations. Because the product is benign, blocking it requires an explicit organizational policy rather than an automated EDR rule.

Phase 7: Encryption and inhibited recovery

Before launching encryption, the affiliate executes an obfuscated command (cmd.exe /c vssadmin delete shadows /all) to eliminate Volume Shadow Copies. The encryptor is subsequently executed via the command line:

Encryptor.exe /lkey:"<32-byte-key>" /encrypt_step:40 /work_mode:local_network

The cryptographic routine uses ECDH over Curve25519 for key exchange alongside AES-256 for file payload encryption. A 60-byte trailer containing the session public key formatted as an ECCPUBLICBLOB is appended to every encrypted file. Affected files are tagged with the .chaos extension, and an obfuscated ransom note (readme.chaos.txt) encrypted on disk with a 25-byte XOR cipher is generated.

The encryptor selectively skips critical system and operational areas, including the Windows, AppData, $recycle.bin, and browser directories, along with boot assets like ntuser.dat and autorun.inf. Preserving these core components keeps the host system bootable and able to load web browsers so the victim can reach the negotiation portal.

MITRE ATT&CK mapping

Mapping attack behaviors to standardized threat frameworks allows security teams to correlate observed technical telemetry with documented adversary tactics. These are Chaos ransomware observed techniques:

TacticTechniqueIDConfidence
Initial AccessSpearphishing VoiceT1598.004Observed
Initial AccessValid AccountsT1078Observed
Initial AccessExternal Remote ServicesT1133Observed
ExecutionWindows Management InstrumentationT1047Observed
ExecutionCommand and Scripting Interpreter: PowerShellT1059.001Observed
PersistenceRemote Access SoftwareT1219Observed
Defense EvasionVirtualization/Sandbox EvasionT1497Observed
Defense EvasionDebugger EvasionT1622Observed
Lateral MovementRemote Services: RDPT1021.001Observed
Lateral MovementRemote Services: SMBT1021.002Observed
ExfiltrationExfiltration Over Web ServiceT1567Observed
ImpactData Encrypted for ImpactT1486Observed
ImpactInhibit System RecoveryT1490Observed

What to do if Chaos is active in your environment

When a Chaos ransomware intrusion is actively unfolding, rapid containment and forensic preservation are critical to preventing full-network encryption and mitigating regulatory exposure.

If you suspect an active incident, contact Proven Data emergency ransomware recovery services immediately for 24/7 technical containment.

Contain at the network layer, not the power button

Sever connectivity by disabling switch ports, isolating VLANs, and shutting down the VPN concentrator. Powering hosts off destroys volatile memory that scopes the intrusion. Isolate domain controllers and backup infrastructure first.

Terminate the access path, not just the malware

Persistence can live in installed RMM software, not just a dropped file. Enumerate every remote access agent in the environment against your approved inventory, remove unapproved ones, and revoke their cloud-side sessions at the vendor console. An uninstalled agent whose account remains active is not removed.

Preserve evidence before rebuilding

Capture memory, RMM application logs, Quick Assist session records, mail gateway logs covering the flood, firewall and proxy egress records, and EDR telemetry already forwarded to the cloud console. Exfiltration scoping depends on endpoint-independent egress volume data.

Hunt persistence before restoring

Scheduled tasks, GPO modifications, and service accounts created during the intrusion survive a restore.

"Ransomware deployment often represents the final stage of a much longer intrusion. Responders must investigate both the original intrusion and the ransomware deployment; limiting analysis to the encryption event leaves the entry point unresolved and increases the risk of reinfection," explains Abdelaziz.

Rotate credentials comprehensively

Reset every domain account, reset krbtgt twice, and revoke OAuth grants, API keys, and active sessions. Resets without revocation leave live sessions running.

Assess regulatory exposure immediately

Exfiltration precedes encryption in this operation, so notification clocks may already be running. Counsel needs to determine which apply before they expire.

Does Chaos ransomware have a public decryptor?

No public decryptor exists for the Chaos RaaS group's encryptor. The implementation uses ECDH over Curve25519 to derive a per-victim key with AES-256 for file data, and the public key written into each file's 60-byte appendix provides no path to the private key. No cryptographic flaw has been publicly reported. Check No More Ransom before concluding, as the landscape changes.

Detection, threat hunting, and defensive hardening

The highest-signal observable for Chaos is not a file hash. It is the sequence of an inbound mail flood followed by an unscheduled remote assistance session within the same business day. That pairing is nearly unique to this intrusion pattern and detectable without malware.

The following consolidated checklist aligns instrumentation priorities with core defensive controls.

Neutralize initial access vectors

  • Quick Assist Controls: Restrict or alert on quickassist.exe execution. Any session starting without a corresponding helpdesk ticket warrants immediate triage; block the executable outright where no valid business case exists.
  • Mail Flood Correlation: Correlate email gateway volume spikes with endpoint behavior. An employee receiving hundreds of messages in minutes should automatically raise that user endpoint's EDR alerting sensitivity for 24 hours.
  • Out-of-Band Verification: Enforce out-of-band identity verification procedures for staff following a mail flood, ensuring employees do not rely on communication channels initiated by the caller.
  • External Messaging Restrictions: Restrict external Microsoft Teams tenants from initiating direct contact with internal employees to block secondary social engineering pathways.

Detect and restrict unauthorized tooling

  • RMM Software Inventory: Keep an explicitly approved inventory of remote access software (e.g., AnyDesk, ScreenConnect). Alert immediately on deviations, as unapproved RMM installations are a primary persistence vector.
  • Exfiltration Monitoring: Monitor for file synchronization clients (such as GoodSync) creating outbound sessions from server infrastructure rather than standard user workstations.

Harden infrastructure and recovery paths

  • Shadow Copy Protection: Set high-severity alerts on shadow copy deletion commands (vssadmin delete shadows) regardless of the parent process. This execution is the final reliable warning before encryption begins.
  • Backup Segmentation: Isolate backup infrastructure on dedicated network segments using credentials that do not authenticate against the primary Active Directory domain. Anything reachable from a compromised domain account will be targeted prior to payload execution.
  • Multi-Platform EDR Coverage: Deploy endpoint protection across ESXi hypervisors and Linux environments. Restricting monitoring tools to Windows hosts leaves cross-platform targets unmonitored.
  • Strict Authentication Controls: Enforce Multi-Factor Authentication (MFA) across every remote access path and administrative portal to block access via valid credentials.



Heloise Montini

Written by

Heloise MontiniCybersecurity Content Writer

Cybersecurity writer at Proven Data covering ransomware trends, incident response, and data protection best practices.

Bachelor's degree, Social Communication - Journalism | São Paulo State University (UNESP)What is Generative AI and What are the Security Considerations? | BrightTALKHuman Factor in Organizations | Cruzeiro do Sul Virtual University
Magdy Abdelaziz

Written by

Magdy AbdelazizHead of DFIR

Magdy Abdelaziz is a dedicated cybersecurity professional with over 7 years of extensive experience in digital forensics, incident response, reverse engineering, and security operations. He currently serves as Head of Digital Forensics and Incident Response (DFIR) at Proven Data LLC, leading a multinational team to develop and execute incident response strategies, align security initiatives with business objectives, and manage global-scale incidents.

GIAC Strategic Planning, Policy, and Leadership (GSTRT) | Global Information Assurance CertificationGIAC Enterprise Incident Response (GEIR) | Global Information Assurance CertificationGIAC Certified Forensic Examiner (GCFE) | Global Information Assurance CertificationGIAC Certified Incident Handler (GCIH) | Global Information Assurance CertificationGIAC Certified Forensic Analyst (GCFA) | Global Information Assurance CertificationGIAC Reverse Engineering Malware (GREM) | Global Information Assurance CertificationGIAC Advisory Board Member | Global Information Assurance CertificationFaculty of Law English Section - Ain Shams University / Bachelor of Laws (LL.B.)
Laura Pompeu

Reviewed by

Laura PompeuCybersecurity Content Writer

Content strategist at Proven Data focused on cybersecurity education, threat analysis, and ransomware awareness.

The Cloud Security Onion: Peeling the Layers within the Cloud Security Realm | Women in CyberSecurity (WiCyS)What is Generative AI and What are the Security Considerations? | BrightTALKGoogle AI Essentials | GoogleBachelor's degree, Journalism, Mass Communication & Media Studies, Pontifical Catholic University of Campinas