Chaos is a ransomware-as-a-service operation that emerged in early 2025, likely formed by former BlackSuit/Royal members, offering cross-platform ransomware for Windows, Linux, ESXi, and NAS to affiliates recruited on the RAMP dark web forum, excluding CIS/BRICS countries and hospitals from targeting. Known victims: 49
Objectives
Executive Summary
Chaos is a recently emerged ransomware-as-a-service (RaaS) operation identified in early 2025, likely formed by members of disbanded groups like BlackSuit or Royal. The group offers cross-platform ransomware targeting Windows, Linux, ESXi, and NAS systems, recruiting affiliates through the RAMP dark web forum. Chaos specifically avoids CIS/BRICS countries and hospital sectors but has successfully targeted numerous other industries, leveraging sophisticated tactics to encrypt victim data for financial gain.
Goals & Targeting
Chaos' primary strategic objectives revolve around financial gain through ransomware operations. The group specifically focuses on sectors where the likelihood of successful encryption and payment collection is high, while avoiding high-risk targets like CIS/BRICS countries and critical infrastructure such as hospitals. Their targeting profile suggests a deliberate approach to maximize profits while minimizing exposure to law enforcement or报复 from targeted nations. The group's victims are typically small-to-medium enterprises in industries with less mature cybersecurity defenses, including manufacturing, energy, retail, and logistics.
Enhanced Description
Chaos represents a new breed of cybercriminal organization focusing on the ransomware market. The group emerged in early 2025, and while its direct origins remain unclear, there are strong indicators linking it to individuals with prior experience in BlackSuit or Royal operations. Chaos operates as a RaaS provider, offering affiliates access to cross-platform ransomware designed for Windows, Linux, ESXi, and NAS systems. This indicates a relatively high level of technical sophistication compared to many emerging cybercriminal groups. The group recruits its members through the RAMP dark web forum, which is known for hosting various RaaS offerings. Notably, Chaos has established operational discipline by excluding certain targets—CIS/BRICS countries and healthcare institutions—from their targeting list. This suggests strategic intent to minimize risk while maximizing potential financial gain. Since its first activity in February 2025 through July 2026, Chaos has targeted a diverse range of industries including manufacturing, energy, chemical, and logistics sectors. The group's TTPs involve initial access via phishing, deployment of custom ransomware payloads, data encryption, and subsequent communication with victims for payment demands. Notable campaigns include incidents against companies such as vacaero.com, cstindustries.com, and other high-profile targets across the United States and Canada.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Chaos has demonstrated a high level of operational persistence, with an active campaign timeline from February 2025 to July 2026. The group's targeting methodology focuses on North American industries outside CIS/BRICS, leveraging their affiliate network to distribute malicious payloads through phishing campaigns and exploit kits. Victims have included manufacturing (e.g., challenge-mfg.com), energy (crescentenergyco.com), retail (kdmpop.com), and logistics (wti transport.com). Notably, Chaos has employed a consistent approach of encrypting victim data without decrypting it until payment is made, often leveraging double extortion by threatening to leak stolen information. Their infrastructure appears to rely on compromised servers for command-and-control communication.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the data is moderate. Chaos's operational timeline, victims list, and TTPs are well-documented from available reports. However, gaps exist regarding their specific malware toolset and initial infection vectors (e.g., whether they use zero-day exploits or known vulnerabilities). Additionally, little is known about the group's long-term goals beyond financial gain, which limits predictive insights.
No techniques linked yet.
No tools linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
43
Campaigns
73
IOCs
0
Observed Data
0
Tactics