BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Chaos Malware Variant Now Targets Cloud Deployments

Chaos malware variant targets cloud, adds proxy to monetize botnet.

  • A new variant of the Chaos malware is now targeting misconfigured cloud deployments, expanding its reach from routers and edge devices.
  • The malware, an evolution of the Kaiji botnet, can mine cryptocurrency, launch DDoS attacks, and now includes a new SOCKS proxy feature to help hide attacker traffic.
  • Cybersecurity firm Darktrace identified the attack, linking the command server domain to infrastructure previously used by the Chinese cybercrime group Silver Fox.

In April 2026, cybersecurity researchers from Darktrace discovered an evolved version of the Chaos malware actively exploiting misconfigurations in cloud deployments, according to a new report. First documented in 2022, this cross-platform malware can execute remote commands, propagate to other systems, and carry out crypto-mining and DDoS attacks.

- Advertisement -

Researchers assess the threat is an evolution of the Kaiji DDoS malware known for targeting Docker instances. Consequently, the malware’s operators remain unknown, though the use of Chinese infrastructure suggests a possible origin.

Darktrace observed the attack on a deliberately misconfigured Hadoop honeypot last month. The intrusion began with an HTTP request that embedded shell commands to download and execute the Chaos binary from an attacker-controlled server.

An interesting connection emerged, as the command domain was previously used by the Silver Fox group in Operation Silk Lure, a phishing campaign delivering ValleyRAT malware. This link provides context to the threat actor’s potential ecosystem and past activities.

The new variant is a restructured 64-bit ELF binary that removes functions for spreading via SSH. Meanwhile, it introduces a significant new SOCKS proxy capability, allowing compromised systems to relay malicious traffic and better conceal the attack’s source.

- Advertisement -

Darktrace noted the removal suggests the threat actors have extensively refactored the code. The addition of the proxy feature indicates a shift to monetize the botnet beyond crypto-mining and DDoS-for-hire services.

“While Chaos is not a new malware, its continued evolution highlights the dedication of cybercriminals to expand their botnets and enhance the capabilities at their disposal,” the report concluded. This trend, seen also in botnets like AISURU, shows DDoS is no longer the sole risk posed by such networks.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

npm Staged Publishing Requires Human Approval

GitHub has introduced mandatory two-factor approval for npm package releases to combat software supply...

Hayes Picks Hyperliquid, Slams Other Altcoins

Arthur Hayes predicts a global "Hunger Games of debt issuance" will drive Bitcoin to...

Bitcoin ETF Outflows Signal Buying Opportunity

Analysts at Santiment suggest recent heavy outflows from U.S. spot Bitcoin ETFs could signal...

Hedera Contracts Now Verifiable on Sourcify

Hedera Mainnet (chain ID 295) and Testnet (chain ID 296) are now natively supported...

Criminal VPN Service Dismantled in Global Operation

A criminal VPN service used by at least 25 ransomware groups was dismantled in...

Must Read

How To Buy a Handshake Domain: A Step-by-Step Guide

Handshake Domains | Benefits | Drawbacks | How To Buy | Supported BrowsersIn this step-by-step guide, I am going to show you how to...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading