Secplicity Blog

Cybersecurity Headlines & Trends Explained

Ransomware Tracker (Entry #239): Chaos v3.0

Entry: https://www.watchguard.com/wgrd-security-hub/ransomware-tracker/chaos-v30

Note: This page is dedicated to the Chaos v3.0 ransomware builder and does not reflect any encryptors created from the builder.

Note: This is the second iteration of the Chaos ransomware builder series. For preliminary information, see the Chaos v1.0 and Chaos v2.0 entries.

Note: A decryptor exists for Chaos v3.0 through Yashma. See below.

 

The Chaos v3.0 builder is similar to Chaos v2.0. However, this is the first iteration of Chaos that truly encrypts files instead of only wiping them. Here are the main differences:

  • You have the option to encrypt files or wipe them. If you choose to encrypt files, it will only do so for files 1 MB or less, using AES-256-CBC. All files larger than 1 MB are wiped.
  • The encryption scheme borrows from the open-source Hidden Tear ransomware.
  • Minor tweaks to random data generation.
  • Expanded target files list.
  • Builder comes with a decryptor generator, too.
Filed under: Ransomware, Research