Secplicity Blog

Cybersecurity Headlines & Trends Explained

Ransomware Tracker (Entry #241): Chaos v5.0

Entry: https://www.watchguard.com/wgrd-security-hub/ransomware-tracker/chaos-v50

Note: This page is dedicated to the Chaos v5.0 ransomware builder and does not reflect any encryptors created from the builder.

Note: This is the second iteration of the Chaos ransomware builder series. For preliminary information, see the Chaos v1.0, Chaos v2.0, Chaos v3.0, and Chaos v4.0 entries.

Note: A decryptor exists for Chaos v3.0 through Yashma. See below.

 

The Chaos v5.0 builder expands on the Chaos v4.0 builder with only minor differences. They are:

  • The encryption algorithm now allows users to encrypt all files. The source code includes functions for "AES_Encrypt_Large" and "AES_Encrypt_Small."
  • Task Manager disabling.
  • Random salt generation.
  • More granular system checks for encryption algorithms.
  • A refined decryptor.
Filed under: Ransomware, Research