Related Threat Clusters
-
Iranian APT MuddyWater Uses Chaos Ransomware as a False Flag for Espionage
In early 2026, the Iranian APT group MuddyWater, affiliated with the Ministry of Intelligence and Security, executed a sophisticated cyber operation disguised as a Chaos ransomware attack. Utilizing social engineering…
17 articles · Updated May 7, 2026 -
Chaos Malware Variant Targets Misconfigured Linux Cloud Servers
A new variant of Chaos malware, originally targeting routers, has been observed exploiting misconfigured Linux cloud servers. This development was documented by Darktrace's CloudyPots program, which captures attacker…
3 articles · Updated April 8, 2026 -
Vishing Campaigns Target Organizations via Microsoft Teams and New Operator Console
A vishing campaign, tracked as STAC4749, targeted North American organizations from February to June 2026, using Microsoft Teams to impersonate IT personnel and gain remote access. Attackers deployed a modular toolset,…
9 articles · Updated July 29, 2026 -
Chaos Ransomware Deploys msaRAT to Evade Detection via Browsers
The Chaos ransomware group has introduced a new Rust-based remote access trojan (RAT) named msaRAT, which disguises command-and-control (C2) traffic through legitimate web browsers like Chrome and Microsoft Edge. By…
8 articles · Updated July 23, 2026 -
Google API Key Vulnerability Exposes Gemini AI Access in Android Apps
A vulnerability in Google's API key system has allowed unauthorized access to the Gemini AI platform from numerous Android applications. CloudSEK identified that existing API keys, meant for public services,…
2 articles · Updated April 10, 2026 -
Ransomware Fuels Surge in Global Cyberattacks
As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…
1922 articles · Updated February 12, 2026 -
Ransomware Threats Intensify for Mid-Market Firms in 2026
Ransomware attacks are increasingly targeting mid-market firms, with two-thirds reporting breaches in the past year. The rise of Ransomware-as-a-Service (RaaS) has made these attacks more accessible to less…
19 articles · Updated January 6, 2026
Recent Intelligence Reports
- Hackers Pose as IT Helpdesk on Microsoft Teams to Deploy Chaos Ransomware — Gbhackers · July 30, 2026
- New Chaos Ransomware — blog.talosintelligence.com · July 29, 2026
- Chaos ransomware deploys browser — Securityaffairs.Co · July 23, 2026
- Chaos ransomware uses browser — Feeds.4Sysops · July 23, 2026
- Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge — Thehackernews · July 23, 2026
- Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process — Feeds2.Feedburner · July 23, 2026
- Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel — Blog.Talosintelligence · July 23, 2026
- Tr Muddying Tracks State Sponsored Shadow Behind Chaos Ransomware — www.rapid7.com · May 11, 2026