Masks, Monsters, and Drivers : Inside the Chaos, Kraken, and DeadLock Ransomware Operations - Cybersecurity Conference

Masks, Monsters, and Drivers : Inside the Chaos, Kraken, and DeadLock Ransomware Operations

The modern Ransomware-as-a-Service (RaaS) ecosystem has evolved beyond simple file encryption into a complex landscape of psychological operations, identity deception, and aggressive defense evasion. This presentation provides a comparative technical analysis of three emerging threats—Chaos, Kraken, and DeadLock—to demonstrate how threat actors are prioritizing misattribution and anti-forensics to outmaneuver defenders.

First, I will talk about the “Identity Deception” trend and examine the new Chaos ransomware, which deliberately adopts the name of an older, unrelated malware builder to confuse attribution efforts, masking its true links to the BlackSuit (Royal) cartel. I will also unveil how Chaos extends this deception all the way into its command-and-control, using a new Rust-based implant, msaRAT, that “lives off the browser”—hiding its network footprint inside the victim’s own Chrome or Edge process. Parallel to this, I will demonstrate the Kraken RaaS analysis and TTPs, a group that has risen from the ashes of the HelloKitty cartel, leveraging its predecessor’s brand while introducing unique cross-platform capabilities and performance benchmarking.

Second, I will pivot to the “Defense Evasion” trend, utilizing exclusive insights into the DeadLock ransomware. Unlike groups focusing solely on branding, DeadLock illustrates the resurgence of “Bring Your Own Vulnerable Driver” (BYOVD) attacks. I will detail how the DeadLock operators use a loader named “EDRGay” to exploit a specific vulnerability (CVE-2024-51324) in the Baidu Antivirus driver disguised with the file name DriverGay.sys to terminate EDR and antivirus processes at the kernel level, clearing the path for a custom stream cipher encryption that utilizes time-based keys.

In this presentation, I will also discuss the attacker’s commands at each stage of the attack chains that enable them to achieve their objectives in the Chaos, Kraken, and DeadLock attacks. Finally, I will conclude the talk with a recommendation for defenders to focus on robust intelligence and strengthening endpoint security.

Mr Chetan Raghuprasad – Cisco Talos

Chetan Raghuprasad is a Cyber Threat Research – Technical Leader with Cisco Talos, specialising in cyber threat intelligence, threat hunting, malware research, reverse engineering, and cybercrime investigations. He focuses on researching the evolving cyber threat landscape, investigating sophisticated attacks and criminal campaigns, and uncovering the tactics, techniques, and procedures (TTPs), motivations, infrastructure, and origins of threat actors to generate actionable intelligence.

With 18 years of experience in Information Security, Chetan has worked across Cyber Threat Intelligence, Cybersecurity Incident Response, Digital Forensics, Threat Hunting, Malware Analysis, and Cybercrime Investigations, analysing cyberattacks and threat campaigns targeting organizations globally. His experience includes investigating complex incidents, analysing malicious tools and infrastructure, profiling threat actors, and correlating technical evidence to understand the broader context of cybercriminal operations. Chetan combines technical threat research with investigative analysis, helping connect malware, infrastructure, victimology, attack techniques, and adversary behaviours to uncover the wider picture behind cybercrime campaigns. His research aims to transform complex technical findings into actionable intelligence that enables organisations and security teams to detect, investigate, disrupt, and defend against evolving threats. Chetan regularly shares his research and expertise through Talos blogs, industry intelligence publications, cybersecurity conferences, and technical presentations worldwide.