Chaos is a ransomware_group tracked across 5 threat clusters and 16 intelligence report mentions on ThreatCluster. First observed January 6, 2026; most recent activity July 23, 2026.
In early 2026, the Iranian APT group MuddyWater, affiliated with the Ministry of Intelligence and Security, executed a sophisticated cyber operation disguised as a Chaos ransomware attack. Utilizing social engineering…
A new variant of Chaos malware, originally targeting routers, has been observed exploiting misconfigured Linux cloud servers. This development was documented by Darktrace's CloudyPots program, which captures attacker…
The Chaos ransomware group has introduced a new Rust-based remote access trojan (RAT) named msaRAT, which disguises command-and-control (C2) traffic through legitimate web browsers like Chrome and Microsoft Edge. By…
A vulnerability in Google's API key system has allowed unauthorized access to the Gemini AI platform from numerous Android applications. CloudSEK identified that existing API keys, meant for public services,…
Ransomware attacks are increasingly targeting mid-market firms, with two-thirds reporting breaches in the past year. The rise of Ransomware-as-a-Service (RaaS) has made these attacks more accessible to less…