Cybersecurity researchers have identified a new variant of the Chaos, which affects incorrect cloud configurations and expands the botnet.

“ The Chaos malware is increasingly targeting cloud misconfigurations, expanding beyond its traditional focus on routers and edge devices , ” Darktrace said in a new report.
Chaos botnet
Chaos was first documented by Lumen Black Lotus Labs in September 2022. It was presented as cross-platform malware , capable of targeting Windows and Linux environments to execute remote shell commands, install additional modules, spread to other hosts via brute-forcing SSH keys, mine cryptocurrencies, and launch denial-of-service (DDoS) attacks over HTTP, TLS, TCP, UDP, and WebSocket.
See also: Mac: New ClickFix attack abuses Script Editor
The malware is believed to be an evolution of another DDoS malware, known as Kaiji, that has targeted misconfigured Docker instances. It is currently unknown who is behind the malicious operation, but the presence of Chinese characters and the use of China-based infrastructure suggest that the threat actor may be of Chinese origin.

New dangerous variant
Darktrace said it discovered the new variant after targeting its honeypot network last month. It was a deliberate misconfiguration of Hadoop that allowed remote code execution on the service. In the attack detected by the cybersecurity firm, the attack began with an HTTP request to the Hadoop deployment to create a new application.
The application incorporated a shell script to retrieve a Chaos agent binary from a server controlled by the attacker. The script also allowed for setting permissions to allow all users to read, modify, or execute it, then executing the binary and deleting it from disk to minimize traces.
An interesting aspect of the attack is that the domain had previously been used in a phishing email campaign carried out by the Chinese cybercrime group Silver Fox to deliver deceptive documents and the ValleyRAT malware .
See also: Zero-day attack targets Adobe Reader users
The 64-bit ELF binary is a refactored and updated version of Chaos, which restructures several of its functions while retaining most of its core features. One of the most significant changes concerns the removal of functions that allowed it to spread via SSH and exploit router vulnerabilities.
In their place is a new SOCKS proxy feature that allows the compromised system to be used for ferrying traffic, thus hiding the real sources of malicious activity and making it more difficult for defenders to detect and block the attack.

“In addition, several functions previously thought to be inherited from Kaiji have now changed, suggesting that threat actors have either rewritten the malware or extensively restructured it,” Darktrace added.
The addition of the proxy feature is likely an indication that threat actors are looking to further exploit the botnet beyond cryptocurrency mining and paid DDoS attacks.
See also: APT28 exploits SOHO routers in DNS Hijacking campaign
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
“While Chaos is not a new malware, its continued evolution highlights cybercriminals’ dedication to expanding their botnets and enhancing the capabilities at their disposal,” Darktrace concluded. “The recent shift in botnets like AISURU and Chaos to include proxy services as core features shows that denial-of-service is no longer the only risk pose these botnets.”
Protection
To protect against threats like Chaos, it is critical to properly secure cloud configurations (especially services like Docker and Hadoop), implement strong passwords and multi-factor authentication (MFA), and restrict access via firewall and network rules to only necessary IPs. At the same time, regular software updates, disabling unnecessary services, using threat detection tools, and constantly monitoring logs can identify suspicious activity early, significantly reducing the risk of a breach.
