In recent times, the action of a type of malware, known as Chaos Ransomware. This ransomware has been active since at least June 2021 and, since then, six different versions have appeared (the latest is called 'Yashma').
Each of these versions originates from a special tool for creating ransomware executables with customised settings. This therefore allows the spread of numerous variants based precisely on this 'builder' developed in NET.
With each new version of this tool, there is the possibility of customising ransomware that is increasingly powerful and complex. To combat the development of this family (and to raise awareness of it), we decided to devote ourselves to analysing the variant 'Mad Cat', which was submitted on Hatching Triage's public sandbox on 24 October 2023. In addition, the report also provides a brief overview of the differences between all versions of the 'Chaos Ransomware' family.
If you wish to learn more, here is the link to our full report.
In addition, you can subscribe to the specific mailing list Cyber Studios by Tinexta Defence, to receive updates on upcoming research: https://tinextadefence.it/mailing-list-cyber-studios/