Chaos Ransomware: BlackSuit-Linked RaaS Resurgence and Detection Opportunities
ID: 8e2b24e4-eced-512b-a247-3615ccfe3127
STIX ID: report--8e2b24e4-eced-512b-a247-3615ccfe3127
Feed Name: Security Boulevard
This report documents the Chaos ransomware family — its origin as a Bagli-derived C# project (2021), multiple forks, and a 2025 re-emergence as a redesigned C++ RaaS offering destructive capabilities, clipboard hijacking for cryptocurrency theft, and double-extortion extortion workflows. Researchers link operators with moderate confidence to former BlackSuit members based on shared encryption and ransom-note patterns. The report details the operation’s multi-stage intrusion chain (email/voice phishing, Microsoft Quick Assist for initial access, deployment of RMM tools such as AnyDesk/ScreenConnect/Syncro, RDP lateral movement, data exfiltration via GoodSync masquerading as a legitimate executable, and final payload deployment), encryption mechanics (AES-256 CFB for files with RSA-1024 key encryption), and common techniques (VSS deletion, debugger/sandbox checks, Startup LNK persistence), and notes AttackIQ emulations for validating defenses against these behaviors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
