Secplicity Blog

Cybersecurity Headlines & Trends Explained

Ransomware Tracker (Entry #240): Chaos v4.0

Entry: https://www.watchguard.com/wgrd-security-hub/ransomware-tracker/chaos-v40

Note: This page is dedicated to the Chaos v4.0 ransomware builder and does not reflect any encryptors created from the builder.

Note: This is the second iteration of the Chaos ransomware builder series. For preliminary information, see the Chaos v1.0, Chaos v2.0, and Chaos v3.0 entries.

Note: A decryptor exists for Chaos v3.0 through Yashma. See below.

 

The Chaos v4.0 builder expands on the Chaos v3.0 builder with similar functionalities. Here are the main differences:

  • The encryption algorithm now allows users to encrypt files up to 2 MB instead of 1 MB.
  • Minor tweaks to random data generation.
  • The target files list is customizable.
  • Now includes ransom note and ability to change the desktop wallpaper.
Filed under: Ransomware, Research