Chaos
MITRE ATT&CK: S0220 View on attack.mitre.org
Aliases: Chaos
- First seen
- 2022-01-01 00:00:00
- Malware type
- backdoor, trojan
- Family
- Malware family
- Operating systems
- linux
- Related IoCs
- 624 (425 malicious)
- Last IoC activity
- 2026-09-02 02:41:00
- Profile updated
- 2026-07-07 13:55:23
Targeted industries: technology-and-telecommunications
Context
Chaos is Linux malware that compromises systems by brute force attacks against SSH services. Once installed, it provides a reverse shell to its controllers, triggered by unsolicited packets.
Recent IoC activity
426 malicious indicators in Maltiverse are attributed to Chaos (S0220). The 20 most recently updated:
Detection coverage
- 4 YARA rules
- 40 Sigma rules
Malware & tools used
- Symmetric Cryptography (attack-pattern)
- Unix Shell (attack-pattern)
- Brute Force (attack-pattern)
- Traffic Signaling (attack-pattern)
- Multi-Stage Channels (attack-pattern)
Detection rules
- BLACKBERRY_Mal_Win32_Chaosransomware_2022 (yara-rule)
- BLACKBERRY_Mal_Win32_Chaos_Builder_Ransomware_2022 (yara-rule)
- BLACKBERRY_Mal_Win32_Onyx_Strain_Chaos_Ransomware_2022 (yara-rule)
- SEKOIA_Ransomware_Win_Chaos (yara-rule)
Related threat objects
- Rincrypt (malware)
Reports & references
- ransomlook.io — Chaos (report)
- Broadcom/Symantec — Chaos Ransomware Group Surfaces With Aggressive Tactics (report)
- cyble.com — Top Ransomware Groups June 2025 Qilin Top Spot (report)
- infosecurity-magazine.com — Chaos Ransomware Wave Attacks (report)
- bleepingcomputer.com — Chaos Ransomware Hits Optima Tax Relief Leaks 69Gb Data (report)
- gosecure.net — Chaos Stolen Backdoor Rising (report)
- MITRE ATT&CK — S0220 (report)