Overview
Platforms:
Windows · Linux (advertised) · VMware ESXi (advertised) · NAS (advertised)
Variants:
—
Extensions:
.chaos
ATT&CK software:
Impacket (S0357)
Initial access:
Valid Accounts
Top countries:
US · GB · CA · DE · AU
Observed sectors:
Technology · Manufacturing · Professional Services · Healthcare · Transportation
Tracked victims:
92
Attribution
BlackSuit / Royal lineage
PROBABLE
Probable predecessor relationship
Cisco Talos assesses with moderate confidence that Chaos is either a rebrand of BlackSuit / Royal or is operated by former members of that ransomware ecosystem.
Affiliates
No affiliate information available.
Activity
Recent Observations
Continued Chaos victim claims
September 2026
Leak-site activity
Chaos continued publishing new victim claims during September 2026.
msaRAT identified
July 2026
Malware development
Cisco Talos identified a new Rust-based remote access trojan attributed to Chaos that uses browser-mediated communications for command and control.
Sustained operational tempo
March 2026
Ransomware activity
Chaos continued conducting double-extortion attacks and maintained a consistent operational tempo during early 2026.
Chaos operations documented
July 2025
Ransomware activity
Cisco Talos documented enterprise intrusions involving social engineering, remote-management tooling, data theft and Chaos ransomware deployment.
TTPs
ATT&CK coverage:
9 techniques
· 8 tactics
T1078
Valid Accounts
VERIFIEDInitial Access
Chaos actors obtain or abuse valid accounts during social-engineering-driven intrusion activity.
T1598.004
Voice Phishing
VERIFIEDReconnaissance / Initial Access
Chaos operators use voice phishing while impersonating IT or security personnel after flooding users with spam messages.
T1219
Remote Access Software
VERIFIEDCommand and Control
Chaos abuses Microsoft Quick Assist and RMM products including AnyDesk, ScreenConnect, OptiTune, Syncro RMM and Splashtop for remote access and persistence.
Show more TTPs (6)
T1059.001
PowerShell
VERIFIEDExecution
Chaos uses PowerShell during post-compromise activity and payload execution.
T1047
Windows Management Instrumentation
VERIFIEDExecution / Lateral Movement
Chaos uses WMI for remote process execution and lateral movement across compromised environments.
T1135
Network Share Discovery
VERIFIEDDiscovery
Chaos operators enumerate accessible network shares and remote systems before exfiltration and encryption.
T1567.002
Exfiltration Over Web Service
VERIFIEDExfiltration
Chaos uses legitimate synchronization and cloud-transfer software such as GoodSync to move stolen data to attacker-controlled storage.
T1490
Inhibit System Recovery
VERIFIEDImpact
Chaos deletes Windows volume shadow copies to interfere with recovery after ransomware deployment.
T1486
Data Encrypted for Impact
VERIFIEDImpact
Chaos performs rapid selective encryption across local and network resources and appends the .chaos extension to encrypted files.
Victims
Mankato Clinic
CLAIMED
Healthcare organization in United States.
CVEs
No CVE associations available.
Infrastructure
Chaos leak site
Chaos operates Tor-hosted data leak infrastructure used to publish victim claims and stolen information as part of its double-extortion model.
RaaS infrastructure
Chaos operates a ransomware-as-a-service ecosystem supporting affiliates conducting big-game hunting and double-extortion attacks.
Chaos C2 infrastructure
Chaos-associated msaRAT uses Chrome DevTools Protocol, Cloudflare Workers signaling and WebRTC communications to establish covert command-and-control channels.
Timeline
2026-09
Continued active operation
Chaos continued publishing new victim claims through its data leak infrastructure in September 2026.
2026-07
msaRAT discovered
Cisco Talos attributed a newly discovered Rust-based browser-mediated remote access trojan to the Chaos ransomware group.
2026-03
Sustained ransomware activity
Chaos maintained a consistent operational tempo and continued double-extortion campaigns during early 2026.
Show more events (2)
2025-07
Chaos RaaS publicly documented
Cisco Talos published detailed incident-response analysis of the new Chaos ransomware operation and its attack methodology.
2025-02
Chaos activity first confirmed
Cisco Talos dates confirmed activity of the new Chaos ransomware-as-a-service operation to February 2025.
Sources
Unmasking the new Chaos RaaS group attacks
Cisco Talos