BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Chaos RaaS Emerges After BlackSuit Takedown, Targets US Firms

  • New Ransomware-as-a-service group Chaos linked to former BlackSuit members after law enforcement actions.
  • Chaos uses phishing, remote tools, and rapid encryption in attacks primarily targeting U.S. organizations.
  • Victims face ransom demands of $300,000 for data recovery and breach reports.
  • U.S. authorities recently seized cryptocurrency valued at over $2.4 million from a Chaos group member.
  • Ransomware attacks dropped 43% in Q2 2025, but new groups and advanced tactics continue to emerge.

A new ransomware-as-a-service (RaaS) group, Chaos, has entered the cybercrime scene in February 2025, with evidence linking it to former BlackSuit operators following the takedown of BlackSuit‘s infrastructure by law enforcement. The group has launched attacks mainly against victims in the United States, demanding ransoms of $300,000 for decryptors and breach details.

- Advertisement -

According to researchers at Cisco Talos, Chaos actors combine phishing emails and voice-based social engineering to trick victims into installing remote desktop tools like Microsoft Quick Assist. After gaining access, attackers deploy additional remote monitoring and management (RMM) tools such as AnyDesk, ScreenConnect, OptiTune, Syncro RMM, and Splashtop to maintain a foothold and steal data.

The ransomware rapidly encrypts files across Windows, ESXi, Linux, and NAS systems. “The ransomware utilizes multi-threaded rapid selective encryption, anti-analysis techniques, and targets both local and network resources, maximizing impact while hindering detection and recovery,” Cisco Talos reported. Attackers exfiltrate data using file-sharing software and attempt to erase evidence by deleting event logs and security tools, according to the researchers.

The new Chaos group is not related to builder variants like Yashma or Lucky_Gh0$t, despite the similar name. The operation reflects a pattern, with the attackers’ tactics, ransom notes, and tool selection closely mirroring those of BlackSuit, which itself was a rebrand of the Royal group—tracing its lineage back to Conti. The shift follows a law enforcement seizure announced as part of Operation Checkmate, targeting BlackSuit‘s dark web sites. No official statement has been released about the takedown.

Recently, the U.S. Federal Bureau of Investigation (FBI) and Department of Justice (DoJ) seized 20.2891382 BTC—valued at over $2.4 million—from a cryptocurrency wallet linked to a Chaos member, known as Hors. The ransomware landscape is seeing similar new entrants like Backups, Bert, BlackFL, BQTLOCK, Gunra, Jackalock, Moscovium, RedFox, and Sinobi. For example, Gunra, reportedly based on Conti, has claimed 13 victims since April 2025.

- Advertisement -

Other ransomware variants are using techniques such as DLL side-loading and fake CAPTCHA lures to distribute Malware like NailaoLocker and Epsilon Red. Reports also show ransomware attacks decreased by 43% in the second quarter of 2025, dropping from 2,074 to 1,180 incidents. Qilin led attack activity, followed by Akira, Play, SafePay, and Lynx.

Despite this drop, experts caution that rebranding and advanced social engineering are enabling ransomware groups to remain active and evolve. For more details, see the reports by Cisco Talos, NCC Group, and CYFIRMA (source, Ransomware.live, CYFIRMA).

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

SourTrade Malware Built in Browser Using Bun Runtime

SourTrade malvertising campaign targets cryptocurrency investors by assembling malware inside the victim's browser using...

Critical Fastjson flaw lets attackers hijack Spring Boot apps

A critical remote code execution vulnerability (CVE-2026-16723, CVSS 9.0) affects Alibaba's Fastjson library versions...

Micron Stock Split 2026? Odds Rise as MU Tops $900

Micron Technology stock has surged above $900, fueling speculation about its first stock split...

North Korea arrests crypto laundering bank hackers

North Korean authorities arrested a group of former state cyber operators and IT specialists...

Morgan Stanley hikes Apple stock target to $364, sees 13% ROI

Apple stock opened Friday at $321 after a 1.30% decline, as tech stocks face...

Must Read

17 Best Cryptocurrency Wallets

If you are looking for a list with the best cryptocurrency wallets, then you've landed on the right page. Cryptocurrency, as we all know,...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading