Uptime Hamster: 10d 5h 41mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Chaos Ransomware

Chaos Ransomware

0 incidentes 0 paises 0 sectores ransomware RU Ultimo: -
Aliases: Yashma
Ver en IntelTracker → APTTrail →
Chaos Ransomware is a Ransomware-as-a-Service (RaaS) group that emerged in February 2025, promoting its cross-platform ransomware on Russian-speaking dark web forums and actively recruiting affiliates. This group is distinct from an older 'Chaos ransomware builder' and its variants, a naming choice that has caused confusion in the cybersecurity community. Assessed with moderate confidence to be composed of former members of the BlackSuit or Royal ransomware gangs, Chaos Ransomware's primary motivation is financial gain through sophisticated extortion schemes. The group is notable for its rapid, selective encryption capabilities, robust anti-analysis techniques, and for expanding its extortion tactics from double extortion to a triple extortion model that includes Distributed Denial of Service (DDoS) attacks. Chaos Ransomware explicitly avoids targeting critical infrastructure such as hospitals and government entities, as well as countries within the BRICS/CIS blocs.

Aliases del actor

Yashma

Actores similares

lockbit3ransomware · 2016qilinransomware · 1933akiraransomware · 1524playransomware · 1268clopransomware · 1254lockbit2ransomware · 1002ransomhubransomware · 842incransomransomware · 832alphvransomware · 731dragonforceransomware · 580
Tipo
ransomware
Pais origen
RU
Motivacion
-
Impacto
73
Actualizado
Fri, 19 Ju

Paises objetivo (SOCRadar)

ArgentinaAustraliaBelgiumBulgariaBrazilCanadaSwitzerlandChinaGermanyDenmark

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesSoftware PublishersReal EstateHospitalsEnterprises & HoldingAccommodationAir TransportationManufacturing