Back to News
Malware/Ransomware

New Chaos Variant Targets Misconfigured Cloud Deployments, Adds SOCKS Proxy

Cyber RTApril 9, 20263 min read
New Chaos Variant Targets Misconfigured Cloud Deployments, Adds SOCKS Proxy

Cybersecurity researchers have identified a new variant of the Chaos malware, targeting misconfigured cloud deployments beyond its initial focus on routers and edge devices. First documented in 2022, Chaos targets Windows and Linux systems for various attacks, including DDoS and cryptocurrency mining. The updated version introduces a SOCKS proxy feature, enhancing its capabilities and monetization potential. The malware's evolution suggests ongoing cybercriminal efforts to expand botnet functionalities.

Cybersecurity researchers have identified a new variant of the Chaos malware, which now targets misconfigured cloud deployments, expanding its reach beyond routers and edge devices. This development marks a significant shift in the botnet's targeting strategy, as noted in a report by Darktrace. Chaos was initially documented by Lumen Black Lotus Labs in September 2022 and is known for its ability to operate across Windows and Linux environments, executing remote shell commands, deploying additional modules, and conducting various malicious activities such as cryptocurrency mining and distributed denial-of-service (DDoS) attacks. The Chaos malware is believed to be an evolution of the Kaiji malware, which previously targeted misconfigured Docker instances. While the identity of the operators behind Chaos remains unknown, the presence of Chinese language characters and the use of infrastructure based in China suggest a possible Chinese origin. Darktrace recently detected the new variant within its honeypot network, which included a deliberately misconfigured Hadoop instance vulnerable to remote code execution. The attack on the Hadoop deployment began with an HTTP request to create a new application, embedding shell commands to download a Chaos agent binary from an attacker-controlled server. The binary was then executed and deleted to minimize forensic evidence. Interestingly, the domain used in this attack had been previously associated with a phishing campaign by the Chinese cybercrime group Silver Fox, known as Operation Silk Lure, which aimed to deliver decoy documents and ValleyRAT malware. The new 64-bit ELF binary of Chaos is a restructured version that retains most of its core features but removes functions related to spreading via SSH and exploiting router vulnerabilities. Instead, it introduces a SOCKS proxy feature, allowing compromised systems to be used for traffic routing, thereby obscuring the origins of malicious activities and complicating detection efforts for defenders. Darktrace noted that several functions previously thought to be inherited from Kaiji have been altered, indicating that the malware has been either rewritten or extensively refactored. This suggests that the threat actors are actively evolving the malware to enhance its capabilities and maintain competitiveness in the cybercrime market. The inclusion of the proxy feature indicates a strategic move by the threat actors to further monetize the botnet beyond its traditional roles in cryptocurrency mining and DDoS-for-hire services. This diversification reflects a broader trend among cybercriminals to expand their service offerings and adapt to changing market demands. Darktrace concluded that while Chaos is not a new malware, its ongoing evolution underscores the commitment of cybercriminals to expand their botnets and enhance their operational capabilities. The recent integration of proxy services into botnets like AISURU and Chaos demonstrates that these threats now pose a broader range of risks to organizations and their security teams, beyond just denial-of-service attacks.