Threat Group – Unknown operator using the moniker chaos_00019
Threat Type – Rust based backdoor and remote access trojan
Exploited Vulnerabilities – Valid accounts T1078, phishing T1566, DLL sideloading T1574.001, ETW suppression T1562.001, WMI lateral movement T1047
Malware Used – ChaosBot and Fast Reverse Proxy client
Threat Score – 8.0 🔴 High