#ChaosBot
A new Rust-based backdoor called ChaosBot is hijacking corporate networks — and running its C2 over Discord.

It hides behind Microsoft Edge, abuses service accounts, and even checks for VMware to dodge analysis.
#CyberSecurity
thehackernews.com/2025/10/new-...
New Rust-Based Malware "ChaosBot" Uses Discord Channels to Control Victims' PCs
Rust-based ChaosBot exploits Discord and phishing to infiltrate networks, while Chaos-C++ adds data destruction.
thehackernews.com
October 13, 2025 at 6:12 PM
Oh god this is me. Until I run out of energy and become chaosbot.
August 12, 2025 at 9:51 AM
This sounds important..

"Alternatively, the malware has also been observed relying on phishing messages containing a malicious Windows shortcut (LNK) file as a distribution vector. Should the message recipient open the LNK file, a PowerShell command is executed to download and execute ChaosBot ..."
New Rust-Based Malware "ChaosBot" Uses Discord Channels to Control Victims' PCs
Rust-based ChaosBot exploits Discord and phishing to infiltrate networks, while Chaos-C++ adds data destruction.
thehackernews.com
October 18, 2025 at 10:51 AM
⚠️ ChaosBot backdoor, Chaos-C++ evolve

#ChaosBot, a Rust backdoor using Discord C2, LNK phishing and Edge DLL sideloads, enables WMI lateral movement, FRP reverse proxy and ETW/VM evasion. Chaos-C++ adds destructive deletion and clipboard BTC hijack.

#ransomNews #Chaos #malware
October 13, 2025 at 10:42 AM
New Rust-Based ChaosBot Malware Leverages Discord for Stealthy Command and Control
New Rust-Based ChaosBot Malware Leverages Discord for Stealthy Command and Control
cybersecuritynews.com
October 23, 2025 at 7:52 PM
New Rust-Based Malware "ChaosBot" Uses #Discord Channels to Control Victims' PCs 🔥🕵️‍♂️

Researchers have disclosed details of a #Rust-based #backdoor called #ChaosBot that can allow operators to conduct reconnaissance and execute commands on compromised hosts!

thehackernews.com/2025/10/new-...
New Rust-Based Malware "ChaosBot" Uses Discord Channels to Control Victims' PCs
Rust-based ChaosBot exploits Discord and phishing to infiltrate networks, while Chaos-C++ adds data destruction.
thehackernews.com
October 13, 2025 at 8:23 AM
A new Rust-based malware, ChaosBot, hijacks cloud accounts to mine crypto and spread fast. Efficiency meets destruction in the cloud era. ☁️💣 #CloudSecurity #Malware
New Rust-Based Malware "ChaosBot" Uses Discord Channels to Control Victims' PCs
Rust-based ChaosBot exploits Discord and phishing to infiltrate networks, while Chaos-C++ adds data destruction.
buff.ly
October 13, 2025 at 8:05 AM
Chaosbot Using CiscoVPN and Active Directory Passwords for Network Commands gbhackers.com/ciscovpn-and...
Chaosbot Using CiscoVPN and Active Directory Passwords for Network Commands
Adversaries have once again demonstrated that operational hours are irrelevant when mounting sophisticated cyberattacks.
gbhackers.com
October 12, 2025 at 11:08 AM
-PowerSchool hacker sentencing is this week
-Spain arrests major phishing provider
-RDP attack wave targets US
-Aisuru botnet gets US-heavy
-New Brotherhood leak site
-New ChaosBot and ClayRat malware
-New APT35 leaks
-DPRK IT workers now target architects
-New Gladinet zero-day
-NSO has US owners
October 13, 2025 at 10:04 AM
ChaosBot: The Rust-Based Malware Hiding in Plain Sight on Discord

The Rise of a Stealthy Digital Predator In a chilling reminder of how trusted digital spaces can become weapons, cybersecurity researchers have uncovered a new malware strain known as ChaosBot. Written in Rust, this advanced botnet…
ChaosBot: The Rust-Based Malware Hiding in Plain Sight on Discord
The Rise of a Stealthy Digital Predator In a chilling reminder of how trusted digital spaces can become weapons, cybersecurity researchers have uncovered a new malware strain known as ChaosBot. Written in Rust, this advanced botnet uses Discord, the popular chat platform, as its hidden command and control (C2) hub. What makes ChaosBot especially dangerous is its ability to disguise malicious communications as normal, encrypted Discord traffic—allowing it to thrive unnoticed inside corporate and personal networks.
undercodenews.com
October 22, 2025 at 9:03 AM
New Rust-Based Malware “ChaosBot” Uses Discord Channels to Control Victims’ PCs

Oct 13, 2025Ravie LakshmananRansomware / Windows Security Cybersecurity researchers have disclosed details of a new Rust-based backdoor called ChaosBot that can allow operators to conduct reconnaissance and execute…
New Rust-Based Malware “ChaosBot” Uses Discord Channels to Control Victims’ PCs
Oct 13, 2025Ravie LakshmananRansomware / Windows Security Cybersecurity researchers have disclosed details of a new Rust-based backdoor called ChaosBot that can allow operators to conduct reconnaissance and execute arbitrary commands on compromised hosts. "Threat actors leveraged compromised credentials that mapped to both Cisco VPN and an over-privileged Active Directory account named, 'serviceaccount,'" eSentire said in a technical report published last week.
nexttech-news.com
October 13, 2025 at 7:06 AM
Hooo boy.

“Once executed, ChaosBot establishes persistent access by validating its Discord bot token and creating a dedicated private channel named after the victim’s computer.”
New Rust-Based ChaosBot Malware Leverages Discord for Stealthy Command and Control
New Rust-Based ChaosBot Malware Leverages Discord for Stealthy Command and Control
cybersecuritynews.com
October 23, 2025 at 7:55 PM
...RustyAttr, Akira Ransomware (both Akira_v2 and Megazord), Banshee (Rust variant), RALord Ransomware, RustoBot, Tetra Loader, EDDIESTEALER, Myth Stealer, Rustonotto, RustyPages, ChaosBot

This is ~1 new Rust malware family per month. Rust as a programming language for malware is here to stay!
December 15, 2025 at 3:42 PM
The entire industry riding off of OAUTH-inherited permissions is so bad it should be laughed out of the room, and yet because of the mania around these tools, everyone is expected to just give the chaosbot the entirety of your own permissions to every platform.
September 3, 2026 at 12:44 PM
Unbelievable chaos in the best way possible! 🎮😱 Our #ChaosBot strikes again with a spectacular win! Imagine diving into madness and emerging with a random legendary weapon – it's moments like this that make gaming a true adventure. 🏆✨ Who else has experienced this epic #panda-monium? Share your
August 20, 2026 at 2:14 PM
New Rust-Based Malware "ChaosBot" Uses Discord Channels to Control Victims' PCs thehackernews.com/2025/10/new-...
New Rust-Based Malware "ChaosBot" Uses Discord Channels to Control Victims' PCs
Rust-based ChaosBot exploits Discord and phishing to infiltrate networks, while Chaos-C++ adds data destruction.
thehackernews.com
October 16, 2025 at 2:58 AM
New Rust-Based Malware "ChaosBot" Hijacks Discord Channels to Control Victims' PCs

thehackernews.com/2025/10/new-...
New Rust-Based Malware "ChaosBot" Hijacks Discord Channels to Control Victims' PCs
Rust-based ChaosBot exploits Discord and phishing to infiltrate networks, while Chaos-C++ adds data destruction.
thehackernews.com
October 13, 2025 at 5:31 AM
New Rust-Based Malware "ChaosBot" Uses Discord Channels to Control Victims' PCs
New Rust-Based Malware "ChaosBot" Uses Discord Channels to Control Victims' PCs
thehackernews.com
October 13, 2025 at 6:16 AM
New Chaosbot Leveraging CiscoVPN and Active Directory Passwords to Execute Network Commands
New Chaosbot Leveraging CiscoVPN and Active Directory Passwords to Execute Network Commands
cybersecuritynews.com
October 10, 2025 at 3:36 PM
New Rust-Based Malware “ChaosBot” Uses Discord Channels to Control Victims’ PCs

Oct 13, 2025Ravie LakshmananRansomware / Windows Security Cybersecurity researchers have disclosed details of a new Rust-based backdoor called ChaosBot that can allow operators to conduct reconnaissance and execute…
New Rust-Based Malware “ChaosBot” Uses Discord Channels to Control Victims’ PCs
Oct 13, 2025Ravie LakshmananRansomware / Windows Security Cybersecurity researchers have disclosed details of a new Rust-based backdoor called ChaosBot that can allow operators to conduct reconnaissance and execute arbitrary commands on compromised hosts. "Threat actors leveraged compromised credentials that mapped to both Cisco VPN and an over-privileged Active Directory account named, 'serviceaccount,'" eSentire said in a technical report published last week.
nexttech-news.com
October 13, 2025 at 7:05 AM