BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Chaos Malware Variant Now Targets Cloud Deployments

Chaos malware variant targets cloud, adds proxy to monetize botnet.

  • A new variant of the Chaos malware is now targeting misconfigured cloud deployments, expanding its reach from routers and edge devices.
  • The malware, an evolution of the Kaiji botnet, can mine cryptocurrency, launch DDoS attacks, and now includes a new SOCKS proxy feature to help hide attacker traffic.
  • Cybersecurity firm Darktrace identified the attack, linking the command server domain to infrastructure previously used by the Chinese cybercrime group Silver Fox.

In April 2026, cybersecurity researchers from Darktrace discovered an evolved version of the Chaos malware actively exploiting misconfigurations in cloud deployments, according to a new report. First documented in 2022, this cross-platform malware can execute remote commands, propagate to other systems, and carry out crypto-mining and DDoS attacks.

- Advertisement -

Researchers assess the threat is an evolution of the Kaiji DDoS malware known for targeting Docker instances. Consequently, the malware’s operators remain unknown, though the use of Chinese infrastructure suggests a possible origin.

Darktrace observed the attack on a deliberately misconfigured Hadoop honeypot last month. The intrusion began with an HTTP request that embedded shell commands to download and execute the Chaos binary from an attacker-controlled server.

An interesting connection emerged, as the command domain was previously used by the Silver Fox group in Operation Silk Lure, a phishing campaign delivering ValleyRAT malware. This link provides context to the threat actor’s potential ecosystem and past activities.

The new variant is a restructured 64-bit ELF binary that removes functions for spreading via SSH. Meanwhile, it introduces a significant new SOCKS proxy capability, allowing compromised systems to relay malicious traffic and better conceal the attack’s source.

- Advertisement -

Darktrace noted the removal suggests the threat actors have extensively refactored the code. The addition of the proxy feature indicates a shift to monetize the botnet beyond crypto-mining and DDoS-for-hire services.

“While Chaos is not a new malware, its continued evolution highlights the dedication of cybercriminals to expand their botnets and enhance the capabilities at their disposal,” the report concluded. This trend, seen also in botnets like AISURU, shows DDoS is no longer the sole risk posed by such networks.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Bitcoin logs best monthly gain in a year; May outlook eyed

Bitcoin posted its best monthly return in a year for April, gaining nearly 12%.Historical...

White Tech First MiCA Licensed Crypto Firm in Croatia

WHITE TECH, part of the W Group, has become the first company in Croatia...

Academy Bans AI Acting, Scripts From Oscar Eligibility

The Academy of Motion Picture Arts and Sciences has officially barred AI-generated acting and...

GOOGL Price Target Revised Up After Strong Q1 Earnings

Alphabet Inc's Q1 2026 revenue surged 22% year-over-year to $109.9 billion, significantly exceeding estimates...

AI demand sparks months-long Mac mini, Mac Studio shortage

Apple CEO Tim Cook warned that Mac mini and Mac Studio sales have been...

Must Read

How to Set Up a Simple Bitcoin Tip Jar for Your Site or Stream

QUICK LINKSWhat a tip jar is, in plain wordsWhat you needBuild a payment link that just worksAdd a QR code that actually scansWhere to...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading