Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Desorden Group

Description

Desorden (Disorder in Spanish, previously known as ChaosCC), is a financially motivated hacker group. The group first emerged under the new name Desorden in September 2021, on Raidforums. Today the group maintains users under that name on several popular English-speaking hacking forums, where they share their attacks and ransom demands, and offer databases for sale. The group gained an excellent reputation among the cybercriminal communities due to their successful operations and the unique data that they share and offer for sale.

AI Analysis

· 1 week ago

Executive Summary

Desorden Group (formerly ChaosCC) is a financially motivated hacker collective active since September 2021, known for operating on hacking forums, selling stolen data, and publicly announcing ransom demands. The group has established a reputation in cybercriminal circles for high-quality data leaks and successful attacks.

Goals & Targeting

Desorden Group's primary objective is financial gain through a combination of ransomware operations and data trafficking. By targeting organizations with valuable data assets, the group can extract ransoms and sell sensitive information on underground markets. Their forum-based operations suggest a preference for sectors with high data valuations (e.g., healthcare, finance, government) and infrastructure vulnerabilities that enable successful attacks. The group's public sharing of attack details may also serve as a form of reputational marketing to attract more victims and business opportunities within the cybercrime ecosystem.

Enhanced Description

Desorden Group, named for its disruption-focused approach (Spanish for 'disorder'), transitioned from its prior identity as ChaosCC in 2021. The group maintains a presence on multiple English-speaking hacking forums, where it shares attack details, ransom demands, and sells access to compromised databases. Their operations have earned significant credibility within cybercriminal communities due to the value and exclusivity of their data offerings. While the group's technical methods remain partially opaque, their forum activity and success suggest sophisticated capabilities in data exfiltration, ransomware deployment, and cybercrime monetization. The group's emphasis on data trading indicates a focus on maximizing financial returns through both direct ransom payments and illicit data sales.

Key Capabilities

  • Data exfiltration and monetization through illicit sales
  • Ransomware deployment and negotiation
  • Exploitation of forum-based networks for victim acquisition
  • Custom tool development for attack execution
  • Public announcement of operations to deter law enforcement

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Exfiltration

ATT&CK Techniques

T1059.003 - spear-phishing via malicious documents
T1213 - data theft via remote services
T1566.001 - C2 over DNS for communication

Software / Tooling

Custom phishing kits
Ransomware variants
Data extraction tools

Campaigns & Victims

Desorden Group's campaigns demonstrate a pattern of forum-based operations, with a focus on high-impact ransomware attacks and data monetization. Their operational tempo suggests a continuous cycle of victim targeting, attack execution, and post-exploitation data sales. Notable operations include high-profile ransom demands and the dissemination of stolen databases, often announced publicly on hacking forums to establish credibility and deter law enforcement. The group's activities indicate a preference for targeting poorly secured infrastructure and organizations with limited cybersecurity defenses.

IOC Patterns

  • Spear-phishing emails with malicious Office documents
  • C2 communication using DNS-based tunneling
  • Staged infrastructure on bulletproof hosting services

Recommended Actions

  • Implement advanced email filtering to detect phishing attempts
  • Deploy multi-factor authentication for all remote access points
  • Conduct regular network segmentation to limit lateral movement
  • Monitor DNS traffic for anomalous C2 patterns
  • Subscribe to threat intelligence feeds forDesorden Group-related IOCs

Suggested Tags

APT
ransomware
data-broker
financial-motivated
hacker-forum

Confidence Assessment

Moderate confidence. Available data confirms the group's operational model, forum presence, and financial motivations but lacks detailed technical telemetry. Gaps exist in confirmed TTPs, specific tools used, and targeted sectors/countries. Further analysis of attributed attacks and leaked data would improve accuracy.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
APT
ransomware
data-broker
financial-motivated
hacker-forum

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.