All threat actors

Chaos RaaS Group

Alert me

A ransomware and double-extortion operation that emerged in 2025 and is distinct from the older Chaos ransomware-builder ecosystem. It has used email bombing, vishing, remote-management tools, data theft, and encryption; Cisco Talos assessed that some operators likely came from the BlackSuit/Royal ecosystem.

Also known as

Chaos
Chaos Ransomware as a Service (RaaS) group

Create a free account to see the reports

Sign in or create a free account to see every report that names Chaos RaaS Group.

Create free account