Netskope Threat Labs

Chaos

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Chaos is ransomware and backdoor malware written for the .NET framework that targets Windows systems for file encryption and remote access, with variants extending to Linux. Its widely shared builder has allowed cyberattackers to produce many customized variants, each configuring extensions, ransom notes, and anti analysis checks differently. Most campaigns distribute it through phishing emails and loaders, and the family's accessibility has made it a common tool for low skilled operators.

First seen
April 2022
Last seen
October 2026

5 techniques across 4 tactics.

TA0002 Execution

TA0005 Stealth

TA0006 Credential Access

TA0011 Command and Control

Alert Name
ByteCode-MSIL.Ransomware.Chaos
Document-Word.Virus.Chaos
Gen:Variant.Linux.Chaos.1
Gen:Variant.Ransom.Chaos.107
Gen:Variant.Ransom.Chaos.148
Gen:Variant.Ransom.Chaos.215
Gen:Variant.Ransom.Chaos.30
Gen:Variant.Ransom.Chaos.37
Gen:Variant.Ransom.Chaos.45
Gen:Variant.Ransom.Chaos.6