The Evolution of Chaos Ransomware: Faster, Smarter, and More Dangerous

Oct. 9, 2025, 2:31 p.m.

Description

Chaos ransomware has evolved with a new C++ variant in 2025, marking a significant shift from its .NET origins. This new version combines destructive encryption, clipboard hijacking for cryptocurrency theft, and speed-focused attack strategies. It employs a sophisticated downloader masquerading as a system optimizer, uses AES-256-CFB or XOR encryption, and deletes content of large files instead of encrypting them. The ransomware also implements clipboard hijacking to redirect Bitcoin transactions. Its file traversal strategy has evolved, balancing between efficiency and destructiveness. This evolution demonstrates Chaos's transition towards more aggressive and multifaceted threat tactics, aimed at maximizing financial gain while potentially reducing recovery possibilities for victims.

Date

  • Created: Oct. 9, 2025, 3:41 a.m.
  • Published: Oct. 9, 2025, 3:41 a.m.
  • Modified: Oct. 9, 2025, 2:31 p.m.

Indicators

  • fe717bab60f1b03012b1e6287e3f3725f1ad5163897041b824024aedabb7c46d
  • f4b5b1166c1267fc5a565a861295a20cf357c17d75418f40b4f14b094409d431
  • f200ea7ccc5c9b0eaada74046551ed18a3a9d11c9e87999b25e6b8ee55857359
  • bbf9ebbfd93306108299e54ecbfb59bb9433eeb34f89cef61864f4e87640eaf0
  • 9521a154b06743fcb3a24b6b61ae0b4cbd1f1ba74d3d9cd9110042082d0b1d5c
  • 76fde847037ca79c8e897fac9d80567efc4ec3a193ec3d8ae9c9fcd9e1ac4939
  • 5d3fcf6532c9ee5778753c3f13e71d1e3b157b49e56133bdff5d04d6e6d6c8be
  • 2fb01284cb8496ce32e57d921070acd54c64cab5bb3e37fa5750ece54f88b2a4
  • 19f5999948a4dcc9b5956e797d1194f9498b214479d2a6da8cb8d5a1c0ce3267

Attack Patterns

  • Chaos-C++
  • Lucky_Gh0$t
  • Chaos - S0220
  • BlackSnake
  • Chaos