Desorden (Disorder in Spanish, previously known as ChaosCC), is a financially motivated hacker group. The group first emerged under the new name Desorden in September 2021, on Raidforums. Today the group maintains users under that name on several popular English-speaking hacking forums, where they share their attacks and ransom demands, and offer databases for sale. The group gained an excellent reputation among the cybercriminal communities due to their successful operations and the unique data that they share and offer for sale.
Executive Summary
Desorden Group (formerly ChaosCC) is a financially motivated hacker collective active since September 2021, known for operating on hacking forums, selling stolen data, and publicly announcing ransom demands. The group has established a reputation in cybercriminal circles for high-quality data leaks and successful attacks.
Goals & Targeting
Desorden Group's primary objective is financial gain through a combination of ransomware operations and data trafficking. By targeting organizations with valuable data assets, the group can extract ransoms and sell sensitive information on underground markets. Their forum-based operations suggest a preference for sectors with high data valuations (e.g., healthcare, finance, government) and infrastructure vulnerabilities that enable successful attacks. The group's public sharing of attack details may also serve as a form of reputational marketing to attract more victims and business opportunities within the cybercrime ecosystem.
Enhanced Description
Desorden Group, named for its disruption-focused approach (Spanish for 'disorder'), transitioned from its prior identity as ChaosCC in 2021. The group maintains a presence on multiple English-speaking hacking forums, where it shares attack details, ransom demands, and sells access to compromised databases. Their operations have earned significant credibility within cybercriminal communities due to the value and exclusivity of their data offerings. While the group's technical methods remain partially opaque, their forum activity and success suggest sophisticated capabilities in data exfiltration, ransomware deployment, and cybercrime monetization. The group's emphasis on data trading indicates a focus on maximizing financial returns through both direct ransom payments and illicit data sales.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Desorden Group's campaigns demonstrate a pattern of forum-based operations, with a focus on high-impact ransomware attacks and data monetization. Their operational tempo suggests a continuous cycle of victim targeting, attack execution, and post-exploitation data sales. Notable operations include high-profile ransom demands and the dissemination of stolen databases, often announced publicly on hacking forums to establish credibility and deter law enforcement. The group's activities indicate a preference for targeting poorly secured infrastructure and organizations with limited cybersecurity defenses.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence. Available data confirms the group's operational model, forum presence, and financial motivations but lacks detailed technical telemetry. Gaps exist in confirmed TTPs, specific tools used, and targeted sectors/countries. Further analysis of attributed attacks and leaked data would improve accuracy.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics