logo

Ransomware Tracker (Entry #237): Chaos v1.0

ID: 3a24f05e-1db9-551a-a5a7-a880d431cef6

STIX ID: report--3a24f05e-1db9-551a-a5a7-a880d431cef6

Feed Name: WatchGuard Secplicity Blog

Threat Score
70/100

Date Published: 2025-04-01

Date Updated: 2026-05-01

Author: Ryan Estes

...
...

This WatchGuard entry documents the Chaos ransomware builder family beginning with Chaos v1.0 (first seen June 2021), noting that early builder-produced payloads were destructive wipers that irreversibly overwrite files using a predictable base64-wrapped pattern rather than performing recoverable encryption; it tracks version evolution through v5.0, mentions researcher findings linking probable authors and forks (including Yashma), and lists default behaviors and configuration details of the builder.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.