Chaos RaaS Emerges After BlackSuit Takedown Demanding $300K from U.S. Victims
A law enforcement seizure of BlackSuit's dark web infrastructure suggests that the recently formed Chaos ransomware-as-a-service (RaaS) gang is probably composed of former members of the BlackSuit group.
Chaos, which first appeared in February 2025, is the most recent ransomware to launch double extortion and big game hunting attacks.
According to Cisco Talos researchers Anna Bennett, James Nutland, and Chetan Raghuprasad, Chaos RaaS actors started with low-effort spam flooding and progressed to voice-based social engineering for access, RMM tool abuse for a persistent connection, and legitimate file-sharing software for data exfiltration.
The ransomware maximizes impact while impeding identification and recovery by using multi-threaded quick selective encryption, anti-analysis a...

