Overview

Platforms: Windows · Linux (advertised) · VMware ESXi (advertised) · NAS (advertised)
Variants: —
Extensions: .chaos
ATT&CK software: Impacket (S0357)
Initial access: Valid Accounts
Top countries: US · GB · CA · DE · AU
Observed sectors: Technology · Manufacturing · Professional Services · Healthcare · Transportation
Tracked victims: 92

Attribution

BlackSuit / Royal lineage PROBABLE
Probable predecessor relationship
Cisco Talos assesses with moderate confidence that Chaos is either a rebrand of BlackSuit / Royal or is operated by former members of that ransomware ecosystem.

Affiliates

No affiliate information available.

Activity

Recent Observations

Continued Chaos victim claims
September 2026
Leak-site activity
Chaos continued publishing new victim claims during September 2026.
msaRAT identified
July 2026
Malware development
Cisco Talos identified a new Rust-based remote access trojan attributed to Chaos that uses browser-mediated communications for command and control.
Sustained operational tempo
March 2026
Ransomware activity
Chaos continued conducting double-extortion attacks and maintained a consistent operational tempo during early 2026.
Chaos operations documented
July 2025
Ransomware activity
Cisco Talos documented enterprise intrusions involving social engineering, remote-management tooling, data theft and Chaos ransomware deployment.

TTPs

ATT&CK coverage: 9 techniques · 8 tactics
T1078 Valid Accounts
VERIFIED
Initial Access
Chaos actors obtain or abuse valid accounts during social-engineering-driven intrusion activity.
T1598.004 Voice Phishing
VERIFIED
Reconnaissance / Initial Access
Chaos operators use voice phishing while impersonating IT or security personnel after flooding users with spam messages.
T1219 Remote Access Software
VERIFIED
Command and Control
Chaos abuses Microsoft Quick Assist and RMM products including AnyDesk, ScreenConnect, OptiTune, Syncro RMM and Splashtop for remote access and persistence.
Show more TTPs (6)
T1059.001 PowerShell
VERIFIED
Execution
Chaos uses PowerShell during post-compromise activity and payload execution.
T1047 Windows Management Instrumentation
VERIFIED
Execution / Lateral Movement
Chaos uses WMI for remote process execution and lateral movement across compromised environments.
T1135 Network Share Discovery
VERIFIED
Discovery
Chaos operators enumerate accessible network shares and remote systems before exfiltration and encryption.
T1567.002 Exfiltration Over Web Service
VERIFIED
Exfiltration
Chaos uses legitimate synchronization and cloud-transfer software such as GoodSync to move stolen data to attacker-controlled storage.
T1490 Inhibit System Recovery
VERIFIED
Impact
Chaos deletes Windows volume shadow copies to interfere with recovery after ransomware deployment.
T1486 Data Encrypted for Impact
VERIFIED
Impact
Chaos performs rapid selective encryption across local and network resources and appends the .chaos extension to encrypted files.

Victims

Mankato Clinic CLAIMED
September 2026 United States Healthcare
Healthcare organization in United States.

CVEs

No CVE associations available.

Infrastructure

Chaos leak site
Chaos operates Tor-hosted data leak infrastructure used to publish victim claims and stolen information as part of its double-extortion model.
RaaS infrastructure
Chaos operates a ransomware-as-a-service ecosystem supporting affiliates conducting big-game hunting and double-extortion attacks.
Chaos C2 infrastructure
Chaos-associated msaRAT uses Chrome DevTools Protocol, Cloudflare Workers signaling and WebRTC communications to establish covert command-and-control channels.

Timeline

2026-09
Continued active operation
Chaos continued publishing new victim claims through its data leak infrastructure in September 2026.
2026-07
msaRAT discovered
Cisco Talos attributed a newly discovered Rust-based browser-mediated remote access trojan to the Chaos ransomware group.
2026-03
Sustained ransomware activity
Chaos maintained a consistent operational tempo and continued double-extortion campaigns during early 2026.
Show more events (2)
2025-07
Chaos RaaS publicly documented
Cisco Talos published detailed incident-response analysis of the new Chaos ransomware operation and its attack methodology.
2025-02
Chaos activity first confirmed
Cisco Talos dates confirmed activity of the new Chaos ransomware-as-a-service operation to February 2025.

Sources