BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Chaos Malware Variant Now Targets Cloud Deployments

Chaos malware variant targets cloud, adds proxy to monetize botnet.

  • A new variant of the Chaos malware is now targeting misconfigured cloud deployments, expanding its reach from routers and edge devices.
  • The malware, an evolution of the Kaiji botnet, can mine cryptocurrency, launch DDoS attacks, and now includes a new SOCKS proxy feature to help hide attacker traffic.
  • Cybersecurity firm Darktrace identified the attack, linking the command server domain to infrastructure previously used by the Chinese cybercrime group Silver Fox.

In April 2026, cybersecurity researchers from Darktrace discovered an evolved version of the Chaos malware actively exploiting misconfigurations in cloud deployments, according to a new report. First documented in 2022, this cross-platform malware can execute remote commands, propagate to other systems, and carry out crypto-mining and DDoS attacks.

- Advertisement -

Researchers assess the threat is an evolution of the Kaiji DDoS malware known for targeting Docker instances. Consequently, the malware’s operators remain unknown, though the use of Chinese infrastructure suggests a possible origin.

Darktrace observed the attack on a deliberately misconfigured Hadoop honeypot last month. The intrusion began with an HTTP request that embedded shell commands to download and execute the Chaos binary from an attacker-controlled server.

An interesting connection emerged, as the command domain was previously used by the Silver Fox group in Operation Silk Lure, a phishing campaign delivering ValleyRAT malware. This link provides context to the threat actor’s potential ecosystem and past activities.

The new variant is a restructured 64-bit ELF binary that removes functions for spreading via SSH. Meanwhile, it introduces a significant new SOCKS proxy capability, allowing compromised systems to relay malicious traffic and better conceal the attack’s source.

- Advertisement -

Darktrace noted the removal suggests the threat actors have extensively refactored the code. The addition of the proxy feature indicates a shift to monetize the botnet beyond crypto-mining and DDoS-for-hire services.

“While Chaos is not a new malware, its continued evolution highlights the dedication of cybercriminals to expand their botnets and enhance the capabilities at their disposal,” the report concluded. This trend, seen also in botnets like AISURU, shows DDoS is no longer the sole risk posed by such networks.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Trump Proposes US-Iran Joint Strait of Hormuz Toll

Former President Donald Trump proposed a potential joint venture with Iran to charge tolls...

Cloudflare Targets Quantum-Safe Platform by 2029

Cloudflare announced an accelerated plan to make its entire platform resistant to quantum computing...

Barclays Cuts Robinhood PT, ARK Buys $13M in HOOD

Barclays lowered Robinhood's price target to $89 and downgraded Coinbase to 'Underweight' on lower...

Anthropic’s Mythos Poses Crypto Hacking Peril

Anthropic is granting early access to its powerful "Mythos" AI model to major tech...

South Korea’s new crypto bill targets stablecoins, tokenization

South Korea's ruling party is drafting a bill that would regulate stablecoins as foreign...

Must Read

This is How to Buy and Sell Bitcoin

Now more than ever, there are a variety of ways to enter and exit the crypto market. While this is good, the availability of...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading