Threat Actor

Chaos

Properties

summary
Used the msaRAT Rust implant to route ransomware command-and-control traffic through the victim's own headless Chrome or Edge browser instance.
first_seen
2026-07-27T04:00:26.959997+00:00
last_seen
2026-07-27T04:00:26.959997+00:00
created_at
2026-07-27T04:00:26.959997+00:00
mention_count
1
evidence_url
https://thehackernews.com/2026/07/chaos-ransomware-uses-msarat-to-route.html
target
unknown
provenance
news-scan
scan_confidence
0.8
suspected_origin
unknown
status
pending

Explore this actor's full graph with Ninja Signal