Chaos

S0220

Malware.View on attack.mitre.org

About this malware

Chaos is Linux malware that compromises systems by brute force attacks against SSH services. Once installed, it provides a reverse shell to its controllers, triggered by unsolicited packets.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1059.004
Unix Shell

Chaos provides a reverse shell connection on 8338/TCP, encrypted via AES.

T1104
Multi-Stage Channels

After initial compromise, Chaos will download a second stage to establish a more permanent presence on the affected system.

T1110
Brute Force

Chaos conducts brute force attacks against SSH services to gain initial access.

T1205
Traffic Signaling

Chaos provides a reverse shell is triggered upon receipt of a packet with a special string, sent to any port.

T1573.001
Symmetric Cryptography

Chaos provides a reverse shell connection on 8338/TCP, encrypted via AES.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Chaos Stolen Backdoor Open source
    Sebastian Feldmann. (2018, February 14). Chaos: a Stolen Backdoor Rising Again. Retrieved March 5, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.