Threadlinqs IntelligenceStart free

Threat actorTracked since 2026-07

Chaos

As of 2026-08-29, Chaos is a threat actor tracked by Threadlinqs Intelligence across 5 threats spanning ransomware, malware. ATT&CK coverage spans 63 techniques across 14 tactics in 5 of 5 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1047 (Windows Management Instrumentation), T1057 (Process Discovery).

Tracked threats
55 high
First seen
2026-07-23
Last seen
2026-08-28
ATT&CK techniques
63across 5 of 5 threats
Related CVEs
0None referenced
5 tracked threat(s) · Categories: RANSOMWARE, MALWARE

Activity timeline

Chaos appears in 5 tracked threats between and ; the busiest month was 2026-07 with 3 reports.

ATT&CK techniques observed

63 techniques observed across 5 of 5 tracked threats · Discovery (14), Command and Control (11), Stealth (formerly Defense Evasion) (9), Execution (7), Impact (4), Initial Access (4)
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 5 of 5 tracked threats
  • T1047 Windows Management Instrumentation — Executionobserved in 5 of 5 tracked threats
  • T1057 Process Discovery — Discoveryobserved in 5 of 5 tracked threats
  • T1078 Valid Accounts — Initial Accessobserved in 5 of 5 tracked threats
  • T1490 Inhibit System Recovery — Impactobserved in 5 of 5 tracked threats
  • T1685 Disable or Modify Tools — Defense Impairmentobserved in 5 of 5 tracked threats
  • T1005 Data from Local System — Collectionobserved in 4 of 5 tracked threats
  • T1021 Remote Services — Lateral Movementobserved in 4 of 5 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 4 of 5 tracked threats
  • T1071 Application Layer Protocol — Command and Controlobserved in 4 of 5 tracked threats
  • T1133 External Remote Services — Persistenceobserved in 4 of 5 tracked threats
  • T1219 Remote Access Tools — Command and Controlobserved in 4 of 5 tracked threats
  • T1497 Virtualization/Sandbox Evasion — Stealth (formerly Defense Evasion)observed in 4 of 5 tracked threats
  • T1547 Boot or Logon Autostart Execution — Persistenceobserved in 4 of 5 tracked threats
  • T1567 Exfiltration Over Web Service — Exfiltrationobserved in 4 of 5 tracked threats

Tracked threats