Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Description

Chaos is a ransomware-as-a-service operation that emerged in early 2025, likely formed by former BlackSuit/Royal members, offering cross-platform ransomware for Windows, Linux, ESXi, and NAS to affiliates recruited on the RAMP dark web forum, excluding CIS/BRICS countries and hospitals from targeting. Known victims: 49

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Chaos is a recently emerged ransomware-as-a-service (RaaS) operation identified in early 2025, likely formed by members of disbanded groups like BlackSuit or Royal. The group offers cross-platform ransomware targeting Windows, Linux, ESXi, and NAS systems, recruiting affiliates through the RAMP dark web forum. Chaos specifically avoids CIS/BRICS countries and hospital sectors but has successfully targeted numerous other industries, leveraging sophisticated tactics to encrypt victim data for financial gain.

Goals & Targeting

Chaos' primary strategic objectives revolve around financial gain through ransomware operations. The group specifically focuses on sectors where the likelihood of successful encryption and payment collection is high, while avoiding high-risk targets like CIS/BRICS countries and critical infrastructure such as hospitals. Their targeting profile suggests a deliberate approach to maximize profits while minimizing exposure to law enforcement or报复 from targeted nations. The group's victims are typically small-to-medium enterprises in industries with less mature cybersecurity defenses, including manufacturing, energy, retail, and logistics.

Enhanced Description

Chaos represents a new breed of cybercriminal organization focusing on the ransomware market. The group emerged in early 2025, and while its direct origins remain unclear, there are strong indicators linking it to individuals with prior experience in BlackSuit or Royal operations. Chaos operates as a RaaS provider, offering affiliates access to cross-platform ransomware designed for Windows, Linux, ESXi, and NAS systems. This indicates a relatively high level of technical sophistication compared to many emerging cybercriminal groups. The group recruits its members through the RAMP dark web forum, which is known for hosting various RaaS offerings. Notably, Chaos has established operational discipline by excluding certain targets—CIS/BRICS countries and healthcare institutions—from their targeting list. This suggests strategic intent to minimize risk while maximizing potential financial gain. Since its first activity in February 2025 through July 2026, Chaos has targeted a diverse range of industries including manufacturing, energy, chemical, and logistics sectors. The group's TTPs involve initial access via phishing, deployment of custom ransomware payloads, data encryption, and subsequent communication with victims for payment demands. Notable campaigns include incidents against companies such as vacaero.com, cstindustries.com, and other high-profile targets across the United States and Canada.

Key Capabilities

  • Development and distribution of cross-platform ransomware
  • Recruitment and management of affiliate networks via dark web forums like RAMP
  • Sophisticated data encryption mechanisms
  • Effective communication channels for extorting payments from victims

MITRE ATT&CK Tactics

Cyber Exploitation
Data Destruction

ATT&CK Techniques

T1505
T1485

Software / Tooling

Ransomware payload deployment tools
Spear-phishing kits
Cross-platform encryption utilities

Campaigns & Victims

Chaos has demonstrated a high level of operational persistence, with an active campaign timeline from February 2025 to July 2026. The group's targeting methodology focuses on North American industries outside CIS/BRICS, leveraging their affiliate network to distribute malicious payloads through phishing campaigns and exploit kits. Victims have included manufacturing (e.g., challenge-mfg.com), energy (crescentenergyco.com), retail (kdmpop.com), and logistics (wti transport.com). Notably, Chaos has employed a consistent approach of encrypting victim data without decrypting it until payment is made, often leveraging double extortion by threatening to leak stolen information. Their infrastructure appears to rely on compromised servers for command-and-control communication.

IOC Patterns

  • Spear-phishing emails with malicious links or attachments
  • Ransomware payload delivery through executable files and scripts
  • Encryption of victim files using AES-256 cipher
  • Command-and-control (C2) communication via hardcoded URLs or IP addresses
  • Lateral movement within networks to locate and encrypt sensitive data

Recommended Actions

  • Implement multi-layered email filtering solutions to detect and block phishing attempts
  • Deploy endpoint detection and response (EDR) tools to monitor for异常执行文件的行为
  • Conduct regular backups of critical systems with offline storage options to mitigate ransomware effects
  • Educate employees on recognizing suspicious emails and attachments
  • Analyze network traffic for signs of lateral movement or encryption-based attacks

Suggested Tags

Ransomware
Financial Gain
Cybercriminal Group
Manufacturing Sector
North America
RaaS

Confidence Assessment

Confidence in the data is moderate. Chaos's operational timeline, victims list, and TTPs are well-documented from available reports. However, gaps exist regarding their specific malware toolset and initial infection vectors (e.g., whether they use zero-day exploits or known vulnerabilities). Additionally, little is known about the group's long-term goals beyond financial gain, which limits predictive insights.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

IPV4 12 Domain 1 IPv4 Address 1 SHA-256 Hash 3 MD5 Hash 3

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

43

Campaigns

73

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Healthcare Targeting
Critical Infrastructure
Financial Gain
Cybercriminal Group
Manufacturing Sector
North America
RaaS

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Feb 19, 2025
Last Seen
Aug 5, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.