Activity timeline
Chaos appears in 5 tracked threats between and ; the busiest month was 2026-07 with 3 reports.
ATT&CK techniques observed
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 5 of 5 tracked threats
- T1047 Windows Management Instrumentation — Executionobserved in 5 of 5 tracked threats
- T1057 Process Discovery — Discoveryobserved in 5 of 5 tracked threats
- T1078 Valid Accounts — Initial Accessobserved in 5 of 5 tracked threats
- T1490 Inhibit System Recovery — Impactobserved in 5 of 5 tracked threats
- T1685 Disable or Modify Tools — Defense Impairmentobserved in 5 of 5 tracked threats
- T1005 Data from Local System — Collectionobserved in 4 of 5 tracked threats
- T1021 Remote Services — Lateral Movementobserved in 4 of 5 tracked threats
- T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 4 of 5 tracked threats
- T1071 Application Layer Protocol — Command and Controlobserved in 4 of 5 tracked threats
- T1133 External Remote Services — Persistenceobserved in 4 of 5 tracked threats
- T1219 Remote Access Tools — Command and Controlobserved in 4 of 5 tracked threats
- T1497 Virtualization/Sandbox Evasion — Stealth (formerly Defense Evasion)observed in 4 of 5 tracked threats
- T1547 Boot or Logon Autostart Execution — Persistenceobserved in 4 of 5 tracked threats
- T1567 Exfiltration Over Web Service — Exfiltrationobserved in 4 of 5 tracked threats
Tracked threats
- Chaos Ransomware Claims MacAllister (macallister.com) — 75GB Data Exfiltration Claimed, Leadership Refused EngagementHIGH
- Chaos Ransomware Group Claims 235GB PHI/Internal Document Leak from Healthcare Highways (Unconfirmed)HIGH
- Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and EdgeHIGH
- Chaos Ransomware Deploys Browser-Based msaRAT to Evade Network DetectionHIGH
- Chaos Ransomware Group Deploys msaRAT — Rust-based Malware Abusing Chrome/Edge as C2 Covert ChannelHIGH