Assessment: Chaos presents a high enterprise risk because the name now refers to two related but operationally distinct threat streams: the widely copied Chaos builder that emerged in 2021, and a newer ransomware-as-a-service operation observed from 2025. Early builder versions behaved partly as destructive wipers; later variants supported recoverable encryption. The newer operation conducts human-operated, double-extortion intrusions, combining data theft with encryption and pressure through
chaos ransomware (2)
Activity Summary - Week Ending on 12 November 2021:
- Red Sky Alliance identified 27,845 connections from new IP’s checking in with our Sinkholes
- Analysts identified 3,224 new IP addresses participating in various Botnets
- Sality remains the top Malware Variant at 24,282 Observation
- Chaos Ransomware
- Fake Ecommerce and Black Friday
- Robinhood Hit (Again)
- CISA 22-01
- Ukraine & Gamaredon SSU Arrests
- Pakistan and Russia
- Cyber Attack US Federal Indictments
- FIN7 still Kicking Around
Link to full repo