logo

Unmasking the new Chaos RaaS group attacks

ID: 6e6f954f-212c-58dd-95f6-52f8cf0d4b7a

STIX ID: report--6e6f954f-212c-58dd-95f6-52f8cf0d4b7a

Feed Name: Cisco Talos

Threat Score
78/100

Date Published: 2025-07-24

Date Updated: 2026-04-27

Author: Anna Bennett

...
...

Cisco Talos describes a newly observed RaaS group called "Chaos" conducting big-game hunting double-extortion ransomware attacks across Windows, ESXi, Linux, and NAS systems using social-engineering (including vishing), RMM tool abuse, legitimate file-syncing tools for exfiltration, and a multi-threaded selective-encryptor that appends ".chaos" and deploys a ransom note. The report provides technical analysis of the encryptor (Curve25519 ECDH, AES-256, anti-analysis, shadow copy deletion, selective offset encryption), detailed TTP mappings (MITRE ATT&CK), IOCs, mitigation guidance, and assesses a likely link to BlackSuit/Royal actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.