Chaos (Windows)
Aliases: FakeRyuk, RyukJoke, Yashma
- First seen
- 2021-06-01 00:00:00
- Malware type
- ransomware, trojan
- Family
- Malware family
- Last IoC activity
- 2026-07-21 21:12:30
- Profile updated
- 2026-07-07 13:55:25
Context
In-development ransomware family which was released in June 2021 by an unknown threat actor. The builder initially claimed to be a "Ryuk .Net Ransomware Builder" even though it was completely unrelated to the Ryuk malware family. Presently it appears to contain trojan-like features, but lacks features commonly found in ransomware such as data exfiltration.
Reports & references
- Cisco Talos — New Threat Actor Using Yashma Ransomware (report)
- spamhaus.org — Botnet Threat Update January To June 2025 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Chaos (report)
- threatmon.io — Chaos Unleashed A Technical Analysis Of A Novel Ransomware (report)
- fortinet.com — Chaos Ransomware Variant Sides With Russia (report)
- fortinet.com — Chaos Ransomware Variant In Fake Minecraft Alt List Brings Destruction (report)
- brianstadnicki.github.io — Malware Chaos Ransomware V4 (report)
- research.openanalysis.net — Quasar Chaos (report)
- twitter.com — 1519645742440329216 (report)
- youtube.com — Watch (report)
- blogs.blackberry.com — Yashma Ransomware Tracing The Chaos Family Tree (report)
- blog.qualys.com — The Chaos Ransomware Can Be Ravaging (report)
- marcoramilli.com — The Allegedly Ryuk Ransomware Builder Ryukjoke (report)
- bleepingcomputer.com — Roblox Game Pass Store Used To Sell Ransomware Decryptor (report)
- labs.k7computing.com — Ransomed By Warlock Dark Army Officials (report)
- Trend Micro — Chaos Ransomware A Dangerous Proof Of Concept (report)
- labs.k7computing.com — The Spectre Of Spectraransomware (report)