# Chaos Ransomware Claims MacAllister (macallister.com) — 75GB Data Exfiltration Claimed, Leadership Refused Engagement

> The Chaos ransomware-as-a-service (RaaS) group added macallister.com to its Tor leak site on 2026-08-28 (17:54 UTC), claiming 75GB of exfiltrated data and stating the victim's leadership refused to engage after the breach. Chaos is an active double-extortion RaaS operation, assessed with moderate confidence to be run by former BlackSuit/Royal members, offering cross-platform (Windows/ESXi/Linux/NAS) encryption to affiliates recruited on the RAMP forum.

- **Published:** 2026-08-28T17:54:00Z
- **Last reviewed:** 2026-08-28T17:54:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2209
- **ID:** TL-2026-2209
- **Severity:** HIGH
- **Category:** RANSOMWARE
- **Status:** ACTIVE
- **Actor:** Chaos
- **Detections:** 9 · **IOCs:** 18 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On 2026-08-28 at 17:54 UTC, the Chaos ransomware leak site added a listing for macallister.com, claiming 75GB of exfiltrated data and stating that the victim's leadership refused to engage after being contacted about the incident (ransomware.live: 'Silence will not make this situation go away. Since leadership refuses to engage, we are moving fo...' — text truncated on the tracker page). The listing uses Chaos's characteristic 'blind' countdown-to-publication format. No independent media reporting corroborating the breach was found beyond the ransomware.live tracker (also mirrored by RansomLook); the claim should be treated as unverified pending victim confirmation or data-sample publication, consistent with the HUNT-phase rationale.

A notable discrepancy: ransomware.live classifies the victim's country as United Kingdom (GB), but the domain macallister.com resolves to MacAllister Machinery Co., Inc., a Caterpillar heavy-equipment dealer headquartered at 6300 Southeastern Ave, Indianapolis, Indiana, USA, serving Indiana and Michigan. No UK-registered entity currently operating at that domain was identified (a distinct, unrelated 'MacAllister Limited' UK company registered in Cambridge was dissolved in 2016). This is flagged as an open discrepancy for downstream triage rather than resolved, since the tracker's country tag could reflect an automated misclassification, a distinct international subsidiary not surfaced by search, or an error in the leak-site posting itself.

Chaos is a ransomware-as-a-service operation that re-emerged in February 2025 (first tracked victim 2025-02-19; catalogued by trackers 2025-03-31), distinct from an unrelated, older 'Chaos' ransomware builder that circulated from 2021. Security researchers (Cisco Talos, AttackIQ) assess with moderate confidence that Chaos is operated by former members of the BlackSuit/Royal lineage, based on near-identical encryptor command-line parameter naming (Chaos's `/lkey`, `/encrypt_step`, `/kill_vms` mirror BlackSuit's `-id`, `-ep`, `-stopvm`), matching ransom-note structure and greeting style, and overlapping TTPs. The timing aligns with a DOJ-led international law enforcement action against BlackSuit's infrastructure on 2025-07-24. Chaos recruits affiliates via the RAMP dark-web forum, explicitly excludes CIS/BRICS countries and hospitals from targeting scope, and as of the last 30 days has been one of the more active leak-site operators (85 confirmed victims all-time per ransomware.live, 8 in the trailing 30 days, 6 in the trailing 7 days, with MacAllister posted the same week as Core Materials, Singleton Reynolds, Park de Rochie, and Central Ohio Primary Care).

Chaos's documented attack chain begins with low-effort spam/email flooding escalating to voice-phishing (vishing) calls in which operators impersonate IT/security personnel and direct the target to grant remote access via Microsoft Quick Assist. Access is then handed off to legitimate RMM tools (AnyDesk, ScreenConnect, OptiTune, Syncro RMM, Splashtop Streamer) for persistent connectivity, with Impacket (atexec), WMIC, and PowerShell used for command execution and lateral movement (including RDP), and GoodSync — disguised as a legitimate Windows executable — used for staged data exfiltration ahead of encryption. Prior to encryption, the actors delete Volume Shadow Copies via vssadmin.exe/wmic.exe to inhibit recovery. The encryptor (`encryptor.exe`) performs multi-threaded, selective (`/encrypt_step`-tunable) encryption using ECDH (Curve25519) key exchange with AES-256, appends a 60-byte metadata block, and drops the extension `.chaos` alongside a ransom note `readme.chaos.txt` referencing a victim-specific onion negotiation URL; observed ransom demands include a $300,000 USD figure in prior cases. Extortion is double (data theft + encryption) with the leak site threatening publication, and researchers have documented escalation toward triple/quadruple extortion elements (DDoS threats, threats to notify customers/competitors) in other Chaos cases, though none of those additional elements are yet claimed in the MacAllister posting itself.

Attribution note: a separate Rapid7 research report describes a distinct 'Chaos' branded operation assessed as a false-flag run by the Iranian APT MuddyWater (Seedworm/MOIS-linked), using entirely different tooling (Game.exe, ms_upd.exe, moonzonet[.]com, uploadfiler[.]com, a 'Donald Gay' code-signing certificate, and pythonw.exe process injection) and prioritizing espionage/prepositioning over encryption-based extortion. That reporting does not corroborate or overlap with the BlackSuit/Royal-lineage Chaos RaaS group profiled here (RAMP-recruited affiliates, ESXi/Linux/NAS-capable encryptor, ransomware.live/RansomLook/Talos/AttackIQ-documented infrastructure) and is noted only to avoid downstream conflation of two unrelated threat actors sharing the 'Chaos' name.

## MITRE ATT&CK

- T1598 Phishing for Information
- T1078 Valid Accounts
- T1059 Command and Scripting Interpreter
- T1047 Windows Management Instrumentation
- T1547 Boot or Logon Autostart Execution
- T1036 Masquerading
- T1027 Obfuscated Files or Information
- T1685 Disable or Modify Tools
- T1555 Credentials from Password Stores
- T1057 Process Discovery
- T1033 System Owner/User Discovery
- T1021 Remote Services
- T1005 Data from Local System
- T1567 Exfiltration Over Web Service
- T1219 Remote Access Tools
- T1071 Application Layer Protocol
- T1490 Inhibit System Recovery

## Sources

- [Ransomware.live — MacAllister (Chaos) victim profile](https://www.ransomware.live/id/bWFjYWxsaXN0ZXIuY29tQGNoYW9z)
- [Ransomware.live — Chaos group profile](https://www.ransomware.live/group/chaos)
- [RansomLook — Chaos group profile](https://www.ransomlook.io/group/chaos)
- [Unmasking the new Chaos RaaS group attacks](https://blog.talosintelligence.com/new-chaos-ransomware/)
- [Chaos Ransomware: RaaS Resurgence & Detection](https://www.attackiq.com/2026/07/16/chaos-ransomware/)
- [Novel Chaos Ransomware Group's TTPs Overlap with BlackSuit](https://www.technadu.com/novel-chaos-ransomware-group-attacks-target-businesses-globally-overlaps-with-blacksuit/603990/)
- [MacAllister Machinery — Contact Us (verifies domain ownership/entity)](https://www.macallister.com/about/contact-us/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2209
