Chaos Ransomware is a Ransomware-as-a-Service (RaaS) group that emerged in February 2025, promoting its cross-platform ransomware on Russian-speaking dark web forums and actively recruiting affiliates. This group is distinct from an older 'Chaos ransomware builder' and its variants, a naming choice that has caused confusion in the cybersecurity community. Assessed with moderate confidence to be composed of former members of the BlackSuit or Royal ransomware gangs, Chaos Ransomware's primary motivation is financial gain through sophisticated extortion schemes. The group is notable for its rapid, selective encryption capabilities, robust anti-analysis techniques, and for expanding its extortion tactics from double extortion to a triple extortion model that includes Distributed Denial of Service (DDoS) attacks. Chaos Ransomware explicitly avoids targeting critical infrastructure such as hospitals and government entities, as well as countries within the BRICS/CIS blocs.
Construction of BuildingsFood ManufacturingOther Information ServicesSoftware PublishersReal EstateHospitalsEnterprises & HoldingAccommodationAir TransportationManufacturing