DOJ Seeks Forfeiture of Over $2.3 Million in Bitcoin Linked to Chaos Ransomware Group Member

  • The FBI seized the funds in April 2025 from a wallet associated with the ransomware operator.

  • Chaos operates as a ransomware-as-a-service platform targeting multiple systems since early 2025.

    ‘,

    šŸ”’ Secure and Fast Transactions
    Diversify your investments with a wide range of coins. Join now!

    ‘,

    šŸ’Ž The Easiest Way to Invest in Crypto
    Dont wait to get started. Click now and discover the advantages!


    ];

    var adplace = document.getElementById(“ads-binance”);
    if (adplace) {
    var sessperindex = parseInt(sessionStorage.getItem(“adsindexBinance”));
    var adsindex = isNaN(sessperindex) ? Math.floor(Math.random() * adscodesBinance.length) : sessperindex;
    adplace.innerHTML = adscodesBinance[adsindex];
    sessperindex = adsindex === adscodesBinance.length – 1 ? 0 : adsindex + 1;
    sessionStorage.setItem(“adsindexBinance”, sessperindex);
    }
    })();

  • DOJ seizes $2.3M Bitcoin linked to Chaos ransomware group member ā€œHors.ā€ Discover how authorities are disrupting crypto-enabled cybercrime. Read more on COINOTAG.

    What are the DOJ’s allegations against the Chaos ransomware group?

    The Department of Justice alleges that the seized Bitcoin represents proceeds from illegal activities including extortion and money laundering linked to ransomware attacks. The group member known as ā€œHorsā€ is accused of targeting victims in Texas and beyond, encrypting data, and demanding cryptocurrency payments to restore access and prevent data leaks.

    ‘,

    šŸ”„ The Power of the TRON Ecosystem is Yours!
    Click now to discover exclusive opportunities!

    ‘,

    šŸ’Ž Profit Opportunities on the TRON Network
    Join now to strengthen your investments!


    ];

    var adplace = document.getElementById(“ads-htx”);
    if (adplace) {
    var sessperindex = parseInt(sessionStorage.getItem(“adsindexHtx”));
    var adsindex = isNaN(sessperindex) ? Math.floor(Math.random() * adscodesHtx.length) : sessperindex;
    adplace.innerHTML = adscodesHtx[adsindex];
    sessperindex = adsindex === adscodesHtx.length – 1 ? 0 : adsindex + 1;
    sessionStorage.setItem(“adsindexHtx”, sessperindex);
    }
    })();

    How did the DOJ recover the seized Bitcoin?

    Federal agents accessed the wallet using a recovery seed phrase linked to Electrum, an older Bitcoin wallet platform. The seized cryptocurrency was transferred to a government-controlled address. While specific technical details remain confidential, the DOJ confirmed the funds’ connection to illicit ransomware operations.

    What is the Chaos ransomware group and how does it operate?

    Chaos is a ransomware-as-a-service (RaaS) group active since February 2025. It offers ransomware tools to affiliates who pay a share of ransom profits. The group targets Windows, Linux, ESXi, and NAS systems, encrypting files and threatening to leak sensitive data to extort victims.

    Why is Chaos distinct from other ransomware groups?

    Despite sharing a name with an existing ransomware builder, Chaos appears unrelated and uses the name to obscure its identity. The group’s cross-platform capabilities and aggressive tactics make it a significant threat to individuals and businesses alike.

    How is the DOJ advancing cryptocurrency crime recovery efforts?

    The DOJ collaborates with law enforcement and blockchain firms to recover stolen cryptocurrency. Recent efforts include recovering over $40,000 in USDT linked to scams and filing complaints to seize hundreds of millions in illicit crypto assets. The DOJ’s largest recovery to date involves $9 billion from the 2016 Bitfinex hack.

    CaseAmount RecoveredYear
    Chaos Ransomware Bitcoin Seizure$2.3 Million2025
    Bitfinex Hack Recovery$9 Billion2016-2025
    Tether Scam Recovery$40,300 USDT2025

    What impact does this seizure have on ransomware enforcement?

    The seizure highlights the DOJ’s growing capability to trace and recover cryptocurrency linked to ransomware. It serves as a deterrent to cybercriminals and demonstrates the effectiveness of cross-agency collaboration and blockchain analytics in disrupting illicit crypto flows.

    What challenges remain in combating ransomware groups like Chaos?

    Despite advances, ransomware groups continuously evolve tactics to evade detection. The anonymous nature of cryptocurrency and the use of decentralized platforms complicate enforcement. Ongoing innovation in blockchain forensics and legal frameworks is essential to keep pace.

    Frequently Asked Questions

    How does the DOJ trace cryptocurrency linked to ransomware?

    The DOJ uses blockchain analytics, wallet forensics, and legal tools like recovery seed phrases to identify and seize illicit cryptocurrency assets tied to ransomware activities.

    What is ransomware-as-a-service (RaaS)?

    RaaS is a business model where ransomware developers lease their malware to affiliates who conduct attacks, sharing ransom profits with the developers.

    Key Takeaways

    • DOJ seized over $2.3 million in Bitcoin linked to Chaos ransomware group member ā€œHors.ā€
    • Chaos operates as a ransomware-as-a-service platform targeting multiple operating systems since early 2025.
    • DOJ’s coordinated efforts demonstrate growing success in tracing and recovering illicit cryptocurrency assets.

    Conclusion

    The Department of Justice’s seizure of over $2.3 million in Bitcoin connected to the Chaos ransomware group underscores the increasing effectiveness of law enforcement in combating crypto-enabled cybercrime. As ransomware threats evolve, continued collaboration and innovation in blockchain forensics remain critical to safeguarding digital assets and deterring criminal activity.

    • The U.S. Department of Justice has taken decisive action by filing a civil complaint to forfeit over $2.3 million in Bitcoin linked to a member of the Chaos ransomware group.

    • The FBI successfully seized the cryptocurrency in April 2025 from a wallet controlled by the individual known as ā€œHors.ā€

    • Chaos operates as a ransomware-as-a-service platform, targeting multiple operating systems and extorting victims since early 2025, according to cybersecurity experts at Cisco Talos.

    DOJ seizes $2.3M Bitcoin linked to Chaos ransomware group member ā€œHors.ā€ Discover how authorities are disrupting crypto-enabled cybercrime. Read more on COINOTAG.

    What are the DOJ’s allegations against the Chaos ransomware group?

    The Department of Justice alleges that the seized Bitcoin represents proceeds from illegal activities including extortion and money laundering linked to ransomware attacks. The group member known as ā€œHorsā€ is accused of targeting victims in Texas and beyond, encrypting data, and demanding cryptocurrency payments to restore access and prevent data leaks.

    How did the DOJ recover the seized Bitcoin?

    Federal agents accessed the wallet using a recovery seed phrase linked to Electrum, an older Bitcoin wallet platform. The seized cryptocurrency was transferred to a government-controlled address. While specific technical details remain confidential, the DOJ confirmed the funds’ connection to illicit ransomware operations.

    What is the Chaos ransomware group and how does it operate?

    Chaos is a ransomware-as-a-service (RaaS) group active since February 2025. It offers ransomware tools to affiliates who pay a share of ransom profits. The group targets Windows, Linux, ESXi, and NAS systems, encrypting files and threatening to leak sensitive data to extort victims.

    Why is Chaos distinct from other ransomware groups?

    Despite sharing a name with an existing ransomware builder, Chaos appears unrelated and uses the name to obscure its identity. The group’s cross-platform capabilities and aggressive tactics make it a significant threat to individuals and businesses alike.

    How is the DOJ advancing cryptocurrency crime recovery efforts?

    The DOJ collaborates with law enforcement and blockchain firms to recover stolen cryptocurrency. Recent efforts include recovering over $40,000 in USDT linked to scams and filing complaints to seize hundreds of millions in illicit crypto assets. The DOJ’s largest recovery to date involves $9 billion from the 2016 Bitfinex hack.

    CaseAmount RecoveredYear
    Chaos Ransomware Bitcoin Seizure$2.3 Million2025
    Bitfinex Hack Recovery$9 Billion2016-2025
    Tether Scam Recovery$40,300 USDT2025

    What impact does this seizure have on ransomware enforcement?

    The seizure highlights the DOJ’s growing capability to trace and recover cryptocurrency linked to ransomware. It serves as a deterrent to cybercriminals and demonstrates the effectiveness of cross-agency collaboration and blockchain analytics in disrupting illicit crypto flows.

    What challenges remain in combating ransomware groups like Chaos?

    Despite advances, ransomware groups continuously evolve tactics to evade detection. The anonymous nature of cryptocurrency and the use of decentralized platforms complicate enforcement. Ongoing innovation in blockchain forensics and legal frameworks is essential to keep pace.

    Frequently Asked Questions

    How does the DOJ trace cryptocurrency linked to ransomware?

    The DOJ uses blockchain analytics, wallet forensics, and legal tools like recovery seed phrases to identify and seize illicit cryptocurrency assets tied to ransomware activities.

    What is ransomware-as-a-service (RaaS)?

    RaaS is a business model where ransomware developers lease their malware to affiliates who conduct attacks, sharing ransom profits with the developers.

    Key Takeaways

    • DOJ seized over $2.3 million in Bitcoin linked to Chaos ransomware group member ā€œHors.ā€
    • Chaos operates as a ransomware-as-a-service platform targeting multiple operating systems since early 2025.
    • DOJ’s coordinated efforts demonstrate growing success in tracing and recovering illicit cryptocurrency assets.

    Conclusion

    The Department of Justice’s seizure of over $2.3 million in Bitcoin connected to the Chaos ransomware group underscores the increasing effectiveness of law enforcement in combating crypto-enabled cybercrime. As ransomware threats evolve, continued collaboration and innovation in blockchain forensics remain critical to safeguarding digital assets and deterring criminal activity.

    Don’t forget to enable notifications for our Twitter account and Telegram channel to stay informed about the latest cryptocurrency news.

    Source: https://en.coinotag.com/doj-seeks-forfeiture-of-over-2-3-million-in-bitcoin-linked-to-chaos-ransomware-group-member/