Chaos (Windows)

Aliases: FakeRyuk, RyukJoke, Yashma

First seen
2021-06-01 00:00:00
Malware type
ransomware, trojan
Family
Malware family
Last IoC activity
2026-07-21 21:12:30
Profile updated
2026-07-07 13:55:25

Context

In-development ransomware family which was released in June 2021 by an unknown threat actor. The builder initially claimed to be a "Ryuk .Net Ransomware Builder" even though it was completely unrelated to the Ryuk malware family. Presently it appears to contain trojan-like features, but lacks features commonly found in ransomware such as data exfiltration.

Reports & references

  • Cisco Talos — New Threat Actor Using Yashma Ransomware (report)
  • spamhaus.org — Botnet Threat Update January To June 2025 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Chaos (report)
  • threatmon.io — Chaos Unleashed A Technical Analysis Of A Novel Ransomware (report)
  • fortinet.com — Chaos Ransomware Variant Sides With Russia (report)
  • fortinet.com — Chaos Ransomware Variant In Fake Minecraft Alt List Brings Destruction (report)
  • brianstadnicki.github.io — Malware Chaos Ransomware V4 (report)
  • research.openanalysis.net — Quasar Chaos (report)
  • twitter.com — 1519645742440329216 (report)
  • youtube.com — Watch (report)
  • blogs.blackberry.com — Yashma Ransomware Tracing The Chaos Family Tree (report)
  • blog.qualys.com — The Chaos Ransomware Can Be Ravaging (report)
  • marcoramilli.com — The Allegedly Ryuk Ransomware Builder Ryukjoke (report)
  • bleepingcomputer.com — Roblox Game Pass Store Used To Sell Ransomware Decryptor (report)
  • labs.k7computing.com — Ransomed By Warlock Dark Army Officials (report)
  • Trend Micro — Chaos Ransomware A Dangerous Proof Of Concept (report)
  • labs.k7computing.com — The Spectre Of Spectraransomware (report)

External references