FBI Seizes $24 Million in Bitcoin from Chaos Ransomware Affiliate “Hors” in Major Blow to Cybercrime Ring

Listen to this Post

Featured Image
Introduction: FBI Hits Back at Ransomware in a Landmark Crypto Seizure

In a powerful move against cybercrime, the

This operation not only underscores the

the

On April 15, 2025, the FBI in Dallas seized 20.2891382 Bitcoins (approximately \$2.4 million USD) from a crypto address allegedly linked to a Chaos ransomware affiliate known as “Hors.” This move followed a civil forfeiture complaint filed by the U.S. Attorney’s Office for the Northern District of Texas, spearheaded by Acting U.S. Attorney Nancy E. Larson. According to the complaint, the funds are believed to be proceeds from illegal activity, including money laundering, extortion, and ransomware attacks targeting computer systems—especially in Texas.

The seized crypto address (bc1q5d8af0crjhlnepjq08muhh55899rf2ktye3sxd) was linked directly to criminal operations conducted by Hors, who operated within the Chaos ransomware network. Chaos itself is believed to be the spiritual successor of BlackSuit, which in turn originated from the dissolved Conti cyber gang—a dominant ransomware entity before its collapse in 2022 due to a significant internal leak.

Initially, Chaos ransomware emerged in 2021 as a fake Ryuk clone designed not to encrypt, but to destroy files. However, it quickly morphed into a serious threat, adding encryption, data theft, and obfuscation capabilities. By 2023, it was offered as a ransomware-as-a-service (RaaS) platform, enabling less-skilled attackers to launch sophisticated campaigns. Affiliates like “Hors” used it in targeted extortion operations, particularly in North America.

This development is a major milestone in the ongoing cat-and-mouse game between ransomware gangs and federal law enforcement.

What Undercode Say:

The

1. A Shift in Law Enforcement Strategy

Traditionally, ransomware investigations struggled due to the anonymous and decentralized nature of cryptocurrency. However, this case demonstrates the FBI’s ability to trace and seize crypto assets, even if they’re well-hidden. It signals that blockchain analysis tools and inter-agency cooperation are maturing to the point where criminals can’t rely on Bitcoin for safe harbor anymore.

2. Economic Dismantling of Cyber Gangs

Ransomware-as-a-Service (RaaS) models, like Chaos, rely on monetary incentives to attract affiliates. By cutting off financial rewards—like these Bitcoin seizures—law enforcement undermines the very core of these ecosystems. If affiliates begin to fear they won’t be able to access their earnings, the supply of willing cybercriminals may shrink.

3. The Conti Legacy Continues

Chaos is not just a standalone group. Its connection to Conti and BlackSuit means this is part of a larger ransomware evolution. After Conti’s fall, many affiliates splintered and rebranded, creating new strains like Chaos. The FBI’s action is therefore not just against one actor but part of a long-term containment of a ransomware lineage that has cost organizations millions globally.

4. Texas as a Hotspot

Why Texas? The

5. Future Threats and Decentralization

While this case shows success, the threat remains. Chaos ransomware is still available to other actors, and builder-based malware kits mean that another “Hors” could rise tomorrow. The ransomware industry has decentralized, and unless broader global cooperation and proactive security measures are implemented, the war is far from over.

🔍 Fact Checker Results

✅ The FBI confirmed the seizure of 20.28 BTC from a Chaos ransomware affiliate in Texas.
✅ The cryptocurrency is connected to documented ransomware attacks and tied to known malicious addresses.
✅ Chaos ransomware has historical links to Conti and emerged post-BlackSuit, aligning with expert cyber threat intelligence.

📊 Prediction: Chaos Affiliates Will Shift to Privacy Coins

With

Cybercriminals will adapt—but so will the FBI. The next phase of this battle will depend on who adapts faster.

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: securityaffairs.com
Extra Source Hub:
https://www.reddit.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon