From open source to open threat: Tracking Chaos RAT’s evolution
Chaos RAT is an open-source remote administration tool (RAT) first seen in 2022. It evolved in 2024, and new samples have been discovered by TRU in 2025.













Threat Research Unit is a dedicated Acronis unit composed of experienced cybersecurity experts. Our team includes cross-functional experts in cybersecurity, AI, and threat intelligence. We are empowering IT teams with intelligence-driven cyberthreat research and reporting.
Chaos RAT is an open-source remote administration tool (RAT) first seen in 2022. It evolved in 2024, and new samples have been discovered by TRU in 2025.
EU Vulnerability Database (EUVD) introduced by ENISA to track security vulnerabilities, Facebook users lured by Noodlophile malware spread by fake AI tools, and more. Here are the latest threats to MSP security.
U.K.’s Legal Aid Agency and major retailers are recent victims of DragonForce ransomware group, U.S. firms breached by Luna Moth extortion attackers posing as IT help desks, and more. Here are the latest threats to MSP security.
Acronis Threat Research Unit (TRU) uncovered a new SideWinder APT campaign targeting high-level government institutions in Sri Lanka, Bangladesh and Pakistan.
The Acronis Cyberthreats Update covers current cyberthreat activity and trends, as observed by Acronis Threat Research Unit (TRU) and sensors.
Three known exploited vulnerabilities added to catalog by CISA, North Korean Kimsuky group breaches South Korean and Japanese systems with BlueKeep vulnerability, and more. Here are the latest threats to MSP security.
Cyberattack hits South Africa’s fourth-largest telecom network Cell C, worldwide pharma and health care orgs attacked by new ResolverRAT malware, and more. Here are the latest threats to MSP security.
Microsoft Patch Tuesday for April 2025 addresses 134 vulnerabilities, Precision-validated phishing now being used by threat actors to steal victims’ credentials, and more. Here are the latest threats to MSP security.
Astaroth, also known as Guildma, is a sophisticated piece of malware that first emerged in 2018 and has since undergone significant evolution, adapting to new security measures and refining its attack methodologies.
Data breach hits the State Bar of Texas; INC ransomware gang claims responsibility, Updated version of Hijack Loader uses call stack spoofing to deliver infostealer malware, and more. Here are the latest threats to MSP security.
The Acronis Cyberthreats Update covers current cyberthreat activity and trends, as observed by the Acronis Threat Research Unit.
RedCurl hacking group deploys QWCrypt malware in its initial ransomware campaign, RansomHub’s security evasion tool, EDRKillShifter, exploits vulnerabilities to disable EDR software, and more. Here are the latest threats to MSP security.