Back to Intelligence

CHAOS Ransomware Gang: 2 New Leak-Site Listings — Manufacturing & Healthcare Targeting Analysis with Detection Rules

SA
Security Arsenal Team
September 30, 2026
13 min read

Classification: TLP:CLEAR | Publication Date: 2026-09-30 | Source: ransomware.live leak-site monitoring | Nature of data: Unverified threat-actor claims

Executive Summary

On 2026-09-29, the CHAOS ransomware operation published two new listings on its dark web leak site, naming advantech.com (Manufacturing, Taiwan) and carolinaasthma.com (Healthcare, United States) as alleged victims. Both listings were independently observed by two separate leak-site crawlers, which confirms the gang made these claims — it does not confirm that any breach occurred. Only the named organizations or their regulators can confirm an incident.

The listings are consistent with CHAOS's established pattern: opportunistic double-extortion operations against mid-market organizations in manufacturing and healthcare, sectors where operational downtime creates maximum pressure to pay. Security teams at organizations matching this profile — particularly those with exposed VMware vCenter, Check Point gateways, or Cisco FMC instances — should treat this as a trigger to run the hunt queries in this briefing immediately.

Sourcing & Verification

  • 2 of 2 listings in this dataset were independently observed by a second leak-site crawler (MULTI-SOURCE tier). 0 listings appear on a single source only.
  • Multi-source observation means two independent crawlers saw the gang post the claim. Inclusion in this briefing reflects the threat actor's claim and is NOT confirmation of a breach. No corroboration tier available from leak-site monitoring can confirm that a compromise actually occurred.
  • A named organization may dispute a listing, and a denial is likewise not proof the claim is false. Disclosure obligations vary by jurisdiction and sector, and not every incident is reportable — so neither silence nor denial settles the question definitively.
  • Security Arsenal will publish corrections to this briefing if warranted and welcomes contact from any named organization at security@securityarsenal.com.

Threat Actor Profile — CHAOS

Aliases / lineage: CHAOS is both a ransomware builder/RaaS kit (active since mid-2021, sold on underground forums) and a branding used by multiple semi-autonomous operators. Because the builder is freely traded, leak-site activity attributed to "CHAOS" may originate from different affiliates with overlapping but not identical tradecraft. The current operation runs its own dedicated leak site (DLS) and uses a .chaos extension with Tor-based negotiation portals.

Operating model: Ransomware-as-a-Service. Affiliates handle initial access and deployment; the core group provides the encryptor, negotiation infrastructure, and leak-site hosting. Revenue splits typically favor the affiliate (70–80%).

Ransom demands: Historically in the low-to-mid six figures (USD) for mid-market victims, scaling with perceived ability to pay. CHAOS affiliates are known to discount quickly when victims engage professional negotiators, suggesting cash-flow-driven rather than strategic targeting.

Initial access methods (observed across CHAOS-attributed intrusions):

  • Exploitation of internet-facing remote access: unpatched VPN concentrators and firewalls, exposed RDP, and virtualization management planes
  • Phishing with macro-enabled Office documents and malicious LNK/ISO attachments
  • Purchase of valid credentials from initial access brokers (IABs)
  • Brute force and password-spraying against RDP and VPN portals lacking MFA

Extortion model: Double extortion is standard — data is staged and exfiltrated (commonly via RClone, MEGA, or FTP to actor-controlled infrastructure) before encryption. Non-payers are listed on the DLS with countdown timers and staged data leaks.

Dwell time: Typically short — 24 to 96 hours from initial access to detonation in documented cases. This compresses the defender's window and makes pre-encryption detection (staging, shadow copy deletion, mass file enumeration) the highest-value telemetry.

Current Campaign Analysis

Sectors targeted

The two new listings span Manufacturing and Healthcare — the two sectors CHAOS affiliates have historically favored. Manufacturing offers IT/OT convergence risk and extreme downtime sensitivity; healthcare offers sensitive PHI with strong regulatory pressure and historically thin security budgets at the mid-market tier.

Geographic concentration

One listing each in Taiwan (TW) and the United States (US). The Taiwan manufacturing listing is notable: CHAOS has posted Taiwanese industrial and electronics-sector organizations before, consistent with interest in supply-chain-adjacent manufacturers. The US healthcare listing fits the gang's long-standing pattern against regional clinics and specialty practices rather than large hospital systems.

Victim profile

  • advantech.com — large industrial computing / embedded systems manufacturer headquartered in Taiwan. If the claim involved this organization's corporate environment, the profile would represent a larger-than-typical CHAOS target, potentially indicating an affiliate with more mature access capabilities.
  • carolinaasthma.com — a regional US specialty healthcare practice. This is the archetypal CHAOS victim: mid-market, patient-data-rich, and operationally unable to tolerate extended downtime.

Revenue ranges inferred from sector and size: from low eight figures (regional specialty practice) to nine-plus figures (global manufacturer). This spread is consistent with an affiliate-driven operation taking whatever access it can obtain rather than a tightly curated target list.

Posting frequency / escalation

Two postings on a single day (2026-09-29) after a quiet window suggests either a batch of recently-completed intrusions being published as negotiations stall, or a deliberate attempt to re-establish DLS visibility. Single-day multi-post behavior from CHAOS has historically preceded 1–2 week bursts of additional listings. Monitor the DLS daily through mid-October.

CVE exposure hypothesis (sector-level — NOT victim attribution)

We have no evidence linking any specific CVE to either named listing. However, CHAOS affiliates are known to exploit exactly the class of edge and management-plane vulnerabilities currently on CISA's Known Exploited Vulnerabilities catalog, all confirmed as ransomware-exploited:

  • CVE-2026-50751 — Check Point Security Gateway improper authentication (IKEv1 key exchange). Edge-VPN compromise is a canonical CHAOS entry vector.
  • CVE-2026-20316 — Cisco Secure Firewall Management Center hard-coded password. FMC compromise hands an affiliate centralized firewall control.
  • CVE-2026-59310 — Broadcom VMware vCenter path traversal. vCenter access enables hypervisor-level mass encryption — the highest-impact ransomware outcome.
  • CVE-2026-63077 — JetBrains TeamCity deserialization. Build-server compromise supports supply-chain-style lateral movement and credential theft — especially relevant for manufacturing victims with CI/CD pipelines.
  • CVE-2026-48027 — Nx Console embedded malicious code (supply chain). Developer-workstation footholds align with CHAOS's phishing/tooling-based entry patterns.

Defenders should treat KEV-listed exposure in these products as a priority-one patch/verify item this week, independent of any specific claim.

Detection Engineering

Sigma Rules

YAML
---
title: CHAOS Ransomware - Shadow Copy Deletion via vssadmin or wmic
id: 9e2b7a10-4c3d-4e5a-8f01-chaosvss0001
status: experimental
description: Detects deletion or resizing of Volume Shadow Copies, a near-universal pre-encryption step in CHAOS ransomware deployments.
author: Security Arsenal Threat Intelligence
date: 2026/09/30
references:
  - https://securityarsenal.com/darkside
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    Image|endswith:
      - '\vssadmin.exe'
      - '\wmic.exe'
      - '\diskshadow.exe'
      - '\bcdedit.exe'
  selection_cmd:
    CommandLine|contains:
      - 'delete shadows'
      - 'resize shadowstorage'
      - 'shadowcopy delete'
      - 'recoveryenabled no'
      - 'ignoreallfailures'
  condition: selection_img and selection_cmd
falsepositives:
  - Legitimate backup maintenance scripts (rare on endpoints)
level: high
tags:
  - attack.impact
  - attack.t1490
---
title: CHAOS Ransomware - Data Staging and Exfiltration via RClone or Cloud Sync Tools
id: 9e2b7a10-4c3d-4e5a-8f01-chaosrcl0002
status: experimental
description: Detects execution of RClone or renamed copies commonly used by CHAOS affiliates to exfiltrate staged data to MEGA or actor-controlled storage before encryption.
author: Security Arsenal Threat Intelligence
date: 2026/09/30
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    Image|endswith:
      - '\rclone.exe'
      - '\megacmd.exe'
      - '\winscp.exe'
      - '\filezilla.exe'
  selection_cmd:
    CommandLine|contains:
      - 'copy'
      - 'sync'
      - 'move'
      - '--transfers'
      - '--config'
      - 'mega.nz'
  filter_legit_paths:
    Image|startswith:
      - 'C:\Program Files\RClone\'
      - 'C:\Program Files (x86)\FileZilla'
  condition: (selection_img and selection_cmd) and not filter_legit_paths
falsepositives:
  - IT-managed cloud backup tooling (whitelist known paths/accounts)
level: high
tags:
  - attack.exfiltration
  - attack.t1567
  - attack.t1048
---
title: CHAOS Ransomware - Lateral Movement via PsExec Service Creation or WMI Remote Process
id: 9e2b7a10-4c3d-4e5a-8f01-chaoslat0003
status: experimental
description: Detects PsExec-style remote service installation and WMI-spawned remote processes used by CHAOS affiliates for lateral movement prior to mass encryption.
author: Security Arsenal Threat Intelligence
date: 2026/09/30
logsource:
  product: windows
  service: system
detection:
  selection_psexec:
    EventID: 7045
    Service_Name|contains:
      - 'PSEXESVC'
      - 'PAExec'
      - 'csexecsvc'
  selection_wmi:
    EventID: 7045
    ImagePath|contains:
      - 'cmd.exe /c'
      - 'powershell'
      - '\\ADMIN$\\'
  condition: 1 of selection_*
falsepositives:
  - Legitimate remote administration tools (SCCM, PDQ Deploy) — baseline service names
level: medium
tags:
  - attack.lateral_movement
  - attack.t1021.002
  - attack.t1569.002

KQL — Microsoft Sentinel Hunt Query

KQL — Microsoft Sentinel / Defender
// CHAOS pre-ransomware staging hunt: correlate edge-device logins with
// credential access, staging, and exfil tooling within a 72h window.
let Lookback = 72h;
let SuspiciousTools = dynamic(["rclone.exe","megacmd.exe","psexec.exe","psexesvc.exe","winscp.exe","7z.exe","vssadmin.exe","wmic.exe");
let EdgeLogons =
    SigninLogs
    | where TimeGenerated > ago(Lookback)
    | where AppDisplayName has_any ("VPN","AnyConnect","GlobalProtect","Check Point","FortiGate")
    | where ResultType == 0
    | summarize FirstEdgeLogon=min(TimeGenerated) by UserPrincipalName, IPAddress;
let ToolExec =
    DeviceProcessEvents
    | where TimeGenerated > ago(Lookback)
    | where FileName in~ (SuspiciousTools)
    | project ToolTime=TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine, FolderPath;
ToolExec
| join kind=inner (
    EdgeLogons
    | extend AccountName = tolower(split(UserPrincipalName, "@")[0])
) on AccountName
| where ToolTime between (FirstEdgeLogon .. FirstEdgeLogon + 72h)
| summarize Tools=make_set(FileName), Commands=make_set(ProcessCommandLine), FirstSeen=min(ToolTime), LastSeen=max(ToolTime) by DeviceName, AccountName, IPAddress
| extend HourSpan = datetime_diff("hour", LastSeen, FirstSeen)
| order by FirstSeen asc;
// Secondary pivot: mass file rename/encryption behavior
DeviceFileEvents
| where TimeGenerated > ago(24h)
| where FileName endswith ".chaos" or FileName startswith "DECRYPT" or FileName has "read_me"
| summarize FileOps=count(), SampleFiles=make_set(FileName, 10) by DeviceName, InitiatingProcessFileName
| where FileOps > 50

Rapid-Response PowerShell Script

PowerShell
# CHAOS Rapid Triage - run on suspect hosts or via GPO/Intune across the fleet
# Checks: exposed RDP, shadow copy health, scheduled tasks from last 7 days, staging tools
$Report = @()

# 1. RDP exposure check
$rdp = Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server' -Name fDenyTSConnections -ErrorAction SilentlyContinue
$Report += "[RDP] Enabled: $(if($rdp.fDenyTSConnections -eq 0){'YES - investigate'}else{'No'})"
$rdpNLA = Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name UserAuthentication -ErrorAction SilentlyContinue
$Report += "[RDP] NLA enforced: $(if($rdpNLA.UserAuthentication -eq 1){'Yes'}else{'NO - harden immediately'})"

# 2. Volume Shadow Copy status (CHAOS deletes these pre-encryption)
$shadows = Get-CimInstance Win32_ShadowCopy -ErrorAction SilentlyContinue
$Report += "[VSS] Shadow copies present: $($shadows.Count) $(if($shadows.Count -eq 0){'- WARNING: may indicate deletion'})"

# 3. Scheduled tasks created/modified in last 7 days (persistence + mass-deploy)
$cutoff = (Get-Date).AddDays(-7)
Get-ScheduledTask | Where-Object { $_.Date -gt $cutoff } | ForEach-Object {
    $Report += "[TASK] $($_.TaskName) | Created: $($_.Date) | Action: $($_.Actions.Execute) $($_.Actions.Arguments)"
}

# 4. Staging/exfil tool artifacts (rclone, 7z archives, psexec service)
$toolPaths = @("$env:ProgramData\rclone", "$env:LOCALAPPDATA\rclone", "$env:PUBLIC\*.7z", "$env:PUBLIC\*.zip")
foreach ($p in $toolPaths) { Get-ChildItem $p -Recurse -ErrorAction SilentlyContinue | ForEach-Object { $Report += "[STAGING] $($_.FullName) | Modified: $($_.LastWriteTime)" } }
if (Get-Service PSEXESVC -ErrorAction SilentlyContinue) { $Report += "[LATERAL] PSEXESVC service present - unauthorized PsExec likely" }

# 5. Recently failed logons (brute force signal)
Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4625; StartTime=$cutoff} -MaxEvents 500 -ErrorAction SilentlyContinue |
  Group-Object { $_.Properties[19].Value } | Sort-Object Count -Descending | Select-Object -First 5 |
  ForEach-Object { $Report += "[AUTH] Source IP $($_.Name): $($_.Count) failed logons in 7d" }

$Report | Out-File "$env:TEMP\chaos_triage_$(hostname)_$(Get-Date -Format yyyyMMdd_HHmm).txt"
$Report

Incident Response Priorities

T-minus detection checklist (pre-encryption)

CHAOS's short dwell time means these indicators may all appear within a single 24–72 hour window:

  1. New VPN/edge logons from unusual geographies or ASNs, especially accounts that haven't authenticated remotely in 30+ days
  2. vssadmin delete shadows / bcdedit recoveryenabled no execution anywhere in the fleet — treat as a ransomware precursor until proven otherwise
  3. RClone/MEGA/WinSCP execution outside IT-managed paths, or large outbound transfers (>1 GB) to consumer cloud storage
  4. PsExec service installation (Event 7045) or sudden WMI-spawned processes fanning out from a single host
  5. Mass file enumeration (dir/s, tree, Everything/voidtools) on file servers
  6. GPO or scheduled task changes deploying payloads to multiple endpoints simultaneously
  7. EDR/AV tampering: attempts to uninstall agents, add broad exclusions, or stop security services

Critical assets CHAOS historically prioritizes for exfiltration

  • File servers and NAS shares containing financial records, contracts, and HR data
  • Healthcare-specific: PHI databases, EHR exports, billing records (high pressure-to-pay value)
  • Manufacturing-specific: CAD/CAM files, product designs, supplier and customer lists (IP-theft leverage)
  • Backup servers and backup catalogs (targeted for deletion before encryption)
  • Email archives of executive and legal accounts

Containment actions, ordered by urgency

  1. Isolate, don't power off suspected hosts — preserve memory for forensics while cutting network paths
  2. Disable the compromised identity (and any account that touched it) at the IdP; force global token/session revocation
  3. Block egress to MEGA, anonymous file-sharing, and newly-seen external IPs at the perimeter
  4. Take backup infrastructure offline or read-only — verify an isolated, restorable copy exists now
  5. Segment affected VLANs; if vCenter/FMC is implicated, assume hypervisor and firewall-layer compromise and isolate management planes first
  6. Engage IR retainer and legal/comms counsel before any contact with the actor or public statement

Hardening Recommendations

Immediate (24 hours)

  • Patch or mitigate every KEV-listed edge/management product in your estate: Check Point Security Gateway (CVE-2026-50751), Cisco FMC (CVE-2026-20316), VMware vCenter (CVE-2026-59310), JetBrains TeamCity (CVE-2026-63077), and audit for the malicious Nx Console build (CVE-2026-48027). If patching isn't possible today, pull the management interface off the internet.
  • Enforce MFA on all remote access (VPN, RDP gateways, OWA). CHAOS affiliates buy and brute-force credentialed access; MFA on the edge kills the most common entry path.
  • Block RClone/MEGA/anonymous file-sharing egress at the proxy and alert on any execution of rclone.exe outside IT paths.
  • Alert on shadow copy deletion with a high-severity, page-the-on-call rule (Sigma rule #1 above).
  • Verify backup isolation: confirm at least one offline/immutable backup copy and test a restore this week.

Short-term (2 weeks)

  • Remove RDP from the internet entirely; move remote administration behind a ZTNA broker with device posture checks.
  • Segment the management plane (vCenter, FMC, backup consoles) onto dedicated, ACL-restricted networks reachable only from jump hosts with PAM-controlled, just-in-time credentials.
  • Deploy attack surface monitoring for your external footprint — CHAOS affiliates scan for exactly the products on this week's KEV list; you should know your exposure before they do.
  • Implement egress data-loss controls: baseline normal outbound volume per host and alert on 10x deviations; ransomware exfiltration is loud if you're watching.
  • Tabletop a double-extortion scenario with legal, comms, and leadership — including the leak-site listing decision tree before a countdown timer forces the conversation.
  • Healthcare organizations: review HHS/OCR notification obligations and ensure EHR downtime procedures are current. Manufacturers: validate OT/IT segmentation and confirm historian and HMI systems cannot be reached from the corporate domain.

Analyst Note

Two listings in one day is a small data set — but it arrives alongside five ransomware-confirmed KEV entries covering the exact edge and management-plane products CHAOS affiliates favor. Organizations in manufacturing and healthcare, particularly those matching the mid-market profile described above, should run the hunt content in this briefing this week regardless of whether they have any connection to the named listings. The cost of hunting is low; the cost of being the next listing is not.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.