BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Chaos Malware Variant Now Targets Cloud Deployments

Chaos malware variant targets cloud, adds proxy to monetize botnet.

  • A new variant of the Chaos malware is now targeting misconfigured cloud deployments, expanding its reach from routers and edge devices.
  • The malware, an evolution of the Kaiji botnet, can mine cryptocurrency, launch DDoS attacks, and now includes a new SOCKS proxy feature to help hide attacker traffic.
  • Cybersecurity firm Darktrace identified the attack, linking the command server domain to infrastructure previously used by the Chinese cybercrime group Silver Fox.

In April 2026, cybersecurity researchers from Darktrace discovered an evolved version of the Chaos malware actively exploiting misconfigurations in cloud deployments, according to a new report. First documented in 2022, this cross-platform malware can execute remote commands, propagate to other systems, and carry out crypto-mining and DDoS attacks.

- Advertisement -

Researchers assess the threat is an evolution of the Kaiji DDoS malware known for targeting Docker instances. Consequently, the malware’s operators remain unknown, though the use of Chinese infrastructure suggests a possible origin.

Darktrace observed the attack on a deliberately misconfigured Hadoop honeypot last month. The intrusion began with an HTTP request that embedded shell commands to download and execute the Chaos binary from an attacker-controlled server.

An interesting connection emerged, as the command domain was previously used by the Silver Fox group in Operation Silk Lure, a phishing campaign delivering ValleyRAT malware. This link provides context to the threat actor’s potential ecosystem and past activities.

The new variant is a restructured 64-bit ELF binary that removes functions for spreading via SSH. Meanwhile, it introduces a significant new SOCKS proxy capability, allowing compromised systems to relay malicious traffic and better conceal the attack’s source.

- Advertisement -

Darktrace noted the removal suggests the threat actors have extensively refactored the code. The addition of the proxy feature indicates a shift to monetize the botnet beyond crypto-mining and DDoS-for-hire services.

“While Chaos is not a new malware, its continued evolution highlights the dedication of cybercriminals to expand their botnets and enhance the capabilities at their disposal,” the report concluded. This trend, seen also in botnets like AISURU, shows DDoS is no longer the sole risk posed by such networks.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Drake’s New Song Demands Pardon for SBF

Drake called for the release of imprisoned FTX founder Sam Bankman-Fried in a lyric...

NIO’s Onvo L80 SUV Launches, Deliveries Start Saturday

Nio's mass-market subsidiary, Onvo, officially launched the L80 family SUV on Friday, with deliveries...

Liberland Honors Ethereum Founder Buterin With Star-Shaped Medal

Vitalik Buterin received the "First Class Order of Merit of the Star of Liberland"...

Firm seeks $344M in frozen Tether tied to Iran

Gerstein Harrow LLP is seeking a court order to compel Tether to release over...

Turla’s Kazuar Malware Evolves Into Stealthy P2P Botnet

The Russian state-sponsored group Turla (aka Secret Blizzard) has evolved its Kazuar malware into...

Must Read

Top 10 BEST Crypto Trading Books for New Traders

If you're thinking of diving into the crypto trading space, acquiring solid knowledge isn't just recommended - it's essential to protect your investment.Learning...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading