TT Malware Log

マルウェア / サイバー攻撃 / 解析技術 / 攻撃組織 / 攻撃技術 に関する「個人」の調査・研究

攻撃組織: Chaos (まとめ)

【ニュース】

■2021年

◇2021年10月

◆Chaos ransomware targets gamers via fake Minecraft alt lists (BleepingComputer, 2021/10/30)
[Minecraftの偽のaltリストを使ってゲーマーを狙うランサムウェア「Chaos」が登場]
https://www.bleepingcomputer.com/news/security/chaos-ransomware-targets-gamers-via-fake-minecraft-alt-lists/
https://malware-log.hatenablog.com/entry/2021/10/30/000000_1


■2022年

◇2022年10月

◆New Chaos ransomware variant (PCrisk(Twitter), 2022/10/26)

Ransomware: Chaos, CRYPTONITE
拡張子: 4 random characters, Ransomnote: lisezmoi.txt

https://twitter.com/pcrisk/status/1585141019418320896
https://malware-log.hatenablog.com/entry/2022/10/26/000000_2


■2025年

◇2025年7月

◆BlackSuit Ransomware Group Transitioning to ‘Chaos’ Amid Leak Site Seizure (SecurityWeek, 2025/07/28 06:53)
[BlackSuit Ransomware グループ、リークサイトの押収を受けて「カオス」への移行へ]

The emerging Chaos ransomware appears to be a rebranding of BlackSuit, which had its leak site seized by law enforcement.
[新たなランサムウェア「Chaos」は、そのリークサイトが法執行機関によって押収された「BlackSuit」のブランド名を変更したものと思われます]

https://www.securityweek.com/blacksuit-ransomware-group-transitioning-to-chaos-amid-leak-site-seizure/
https://malware-log.hatenablog.com/entry/2025/07/28/000000_4


◇2025年8月

◆Royal and BlackSuit ransomware gangs hit over 450 US companies (BleepingComputer, 2025/08/08 03:36)
[Royal および BlackSuit ransomware ギャングが 450 社以上の米国企業を攻撃]
https://www.bleepingcomputer.com/news/security/royal-and-blacksuit-ransomware-gangs-hit-over-450-us-companies/
https://malware-log.hatenablog.com/entry/2025/08/08/000000

◆US govt seizes $1 million in crypto from BlackSuit ransomware gang (BleepingComputer, 2025/08/12 12:18)
[米国政府、BlackSuit ransomware ギャングから 100 万ドル相当の暗号通貨を押収]
https://www.bleepingcomputer.com/news/security/us-govt-seizes-1-million-in-crypto-from-blacksuit-ransomware-gang/
https://malware-log.hatenablog.com/entry/2025/08/12/000000_2


■2026年

◇2026年5月

◆Iranian government hackers using Chaos ransomware as cover, researchers say (The Record, 2026/05/08)
[研究者によると、イラン政府のハッカーが「Chaos」ランサムウェアを隠れ蓑にしているという]
https://therecord.media/iran-government-hackers-use-chaos-ransomware-as-cover
https://malware-log.hatenablog.com/entry/2026/05/08/000000_10

◆Rapid7 links Chaos ransomware campaign to Iranian state-sponsored MuddyWater espionage operation (Industrial Cyber, 2026/05/11)
[Rapid7は、ランサムウェア「Chaos」の攻撃キャンペーンを、イラン政府が支援するスパイ活動「MuddyWater」と関連付けている]
https://industrialcyber.co/ransomware/rapid7-links-chaos-ransomware-campaign-to-iranian-state-sponsored-muddywater-espionage-operation/
https://malware-log.hatenablog.com/entry/2026/05/11/000000_4


◇2026年7月

◆Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge (The Hacker News, 2026/07/23)
[Chaosランサムウェア、msaRATを利用してヘッドレスChromeおよびEdge経由でC2トラフィックをルーティング]
https://thehackernews.com/2026/07/chaos-ransomware-uses-msarat-to-route.html
https://malware-log.hatenablog.com/entry/2026/07/23/000000_6

◆Chaosランサムウェアの新バックドア「msaRAT」、ChromeやEdgeブラウザを使ってC2通信をルーティング (Codebook, 2026/07/24)
https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/46838/
https://malware-log.hatenablog.com/entry/2026/07/24/000000_10


【検索】

■Google

google: Chaos Ransomware
google: Chaos ランサムウェア

google:news: Chaos Ransomware
google:news: Chaos ランサムウェア

google: site:virustotal.com Chaos Ransomware
google: site:github.com Chaos Ransomware


■Bing

https://www.bing.com/search?q=Chaos Ransomware
https://www.bing.com/search?q=Chaos ランサムウェア

https://www.bing.com/news/search?q=Chaos Ransomware
https://www.bing.com/news/search?q=Chaos ランサムウェア


■Twitter

https://twitter.com/search?q=%23Chaos Ransomware
https://twitter.com/search?q=%23Chaos ランサムウェア

https://twitter.com/hashtag/Chaos Ransomware
https://twitter.com/hashtag/Chaos ランサムウェア


■VirusTotal

https://www.virustotal.com/gui/search/Chaos Ransomware


【関連まとめ記事】

全体まとめ
 ◆攻撃組織 / Actor (まとめ)

◆サイバー犯罪組織 (まとめ)
https://malware-log.hatenablog.com/entry/Cybercriminal_Group


Copyright (C) 谷川哲司 (Tetsuji Tanigawa) 1997 - 2023