
A sophisticated new ransomware-as-a-service (RaaS) operation called Chaos has emerged in February 2025, likely formed by former BlackSuit crew members following law enforcement seizure of BlackSuit’s dark web infrastructure.
## Advanced Attack Methods
Chaos employs a multi-stage attack strategy that begins with low-effort spam campaigns and escalates to voice-based social engineering. According to Cisco Talos researchers, the group tricks victims into installing remote desktop software, particularly Microsoft Quick Assist, then deploys various remote monitoring and management (RMM) tools including AnyDesk, ScreenConnect, and Splashtop for persistent network access.
The ransomware itself utilizes multi-threaded rapid encryption targeting both local and network resources across Windows, ESXi, Linux, and NAS systems. Chaos demands ransoms of $300,000 in exchange for decryption tools and detailed security recommendations.
## Connection to BlackSuit
Security experts have identified strong links between Chaos and the recently disrupted BlackSuit group through similar encryption commands, ransom note structures, and RMM tool preferences. BlackSuit, itself a rebrand of the Royal ransomware group and Conti offshoot, demonstrates the shape-shifting nature of modern cybercrime organizations.
## Law Enforcement Action
BlackSuit’s dark web sites were seized during Operation Checkmate, a joint international law enforcement effort. The FBI and Department of Justice also announced the seizure of over $2.4 million in Bitcoin from a Chaos member known as “Hors.”
Bitdefender, which assisted in the takedown, reported that BlackSuit claimed over 185 victims since summer 2023. The company emphasized the importance of public-private partnerships in combating organized cybercrime.
## Expanding Ransomware Landscape
Chaos joins numerous new ransomware strains emerging in 2025, including Gunra, which has claimed 13 victims since April and expanded from Windows to Linux systems. Other notable variants include Backups, Bert, BlackFL, and RedFox.
Recent attack methods have evolved to include DLL side-loading techniques and ClickFix-like social engineering tactics that trick users into downloading malicious files disguised as CAPTCHA verification systems.
## Market Trends
Despite the emergence of new groups, NCC Group reports a 43% decline in ransomware attacks during Q2 2025, dropping to 1,180 incidents from 2,074 in Q1. Qilin leads current activity with 151 attacks, followed by Akira (131) and Play (115).
However, experts warn that declining victim numbers don’t indicate reduced threats. Law enforcement actions and leaked ransomware source code may be contributing factors, but groups are adapting through rebranding and advanced social engineering tactics. An estimated 86 ransomware groups remain active in 2025.
