Listen to this Post

A Major Blow to Cybercrime as FBI Strikes Back
In a powerful strike against the growing wave of ransomware attacks, the FBI Dallas Division has confiscated more than \$2.4 million worth of Bitcoin tied to a cybercriminal known as “Hors,” a key member of the Chaos ransomware group. This seizure not only underscores the intensifying federal efforts to dismantle ransomware syndicates but also sheds light on the deep links between recent Texas-based cyberattacks and international ransomware operations. While ransomware gangs continue to evolve and rebrand, this bold move by the FBI sends a message: no one is untouchable, and even in the elusive world of crypto, law enforcement is closing in fast.
FBI Seizes 20 Bitcoin from Chaos Ransomware Affiliate
On April 15, 2025, the FBI Dallas office seized approximately 20.29 BTC, valued at over \$2.3 million, from a cryptocurrency address connected to the Chaos ransomware group. The seizure was directly linked to an affiliate known as “Hors,” believed responsible for orchestrating ransomware attacks and extortion campaigns targeting Texas companies. According to the Department of Justice, the funds were confiscated from wallet address bc1q5d8af0crjhlnepjq08muhh55899rf2ktye3sxd. Following the seizure, on July 24, 2025, the DOJ filed a civil forfeiture complaint to permanently claim the digital assets under federal law.
Civil forfeiture allows authorities to initiate legal action against property involved in criminal activity, sidestepping the need for a criminal conviction. In this case, the Bitcoin was tied to illicit gains from ransomware attacks, justifying the action. The Chaos ransomware group involved is not the same as the low-grade malware of the same name used since 2021. Instead, it’s a rebranded operation believed to stem from the remnants of the Conti group, which disbanded in 2022 after a major data breach. After Conti’s collapse, various factions emerged, including Royal (Quantum), which eventually rebranded as BlackSuit.
By mid-2023, BlackSuit was under pressure from law enforcement and pivoted again, with researchers at Cisco Talos suggesting that the newly branded Chaos ransomware is in fact a continuation of BlackSuit. The latest operation carries forward similar encryption tactics, ransom note structures, and toolkits, linking the lineage from Conti to Royal to BlackSuit and finally to the current Chaos group.
The timing of the seizure is notable: it follows the takedown of BlackSuit’s dark web extortion platforms. It’s believed that this seizure of Bitcoin is a result of investigative leads uncovered during that crackdown. Although the FBI hasn’t officially confirmed whether “Hors” is part of the newly branded Chaos group, cybersecurity sources, including BleepingComputer, confirm that the Bitcoin seizure is indeed linked to this new operation. This incident highlights the growing effectiveness of digital forensics and the FBI’s increasing prowess in tracking crypto assets tied to cybercrime, even in decentralized blockchain ecosystems.
What Undercode Say:
Ransomware Evolution and FBI Adaptation
This seizure is more than just a monetary loss for a criminal—it signals a turning point in cyber law enforcement strategy. The ransomware ecosystem has grown increasingly sophisticated, with gangs like Conti, Royal, and Chaos evolving through rebrands to dodge detection and maintain pressure on victims. However, law enforcement agencies are clearly catching up, using blockchain forensics, crypto tracing, and international cooperation to dismantle the infrastructure behind these syndicates.
The Chaos ransomware group, born from the ashes of the infamous Conti gang, embodies this evolutionary tactic. Rather than launching new malware from scratch, groups are now modifying existing strains, renaming operations, and recruiting affiliates under new banners. What makes Chaos formidable is its inheritance: Conti was one of the most aggressive ransomware operations in history. The organizational knowledge, attack patterns, and criminal connections carried over to Chaos make it a high-level threat.
That said, the recent takedowns—both of websites and wallets—indicate that the “cat and mouse” game is narrowing. The FBI’s ability to locate and confiscate 20 Bitcoin means they either had access to private keys, cooperated with an exchange, or were able to identify vulnerabilities in the affiliate’s operational security. This demonstrates that ransomware actors are not immune from making mistakes, especially when they attempt to launder or move large sums through traceable wallets.
Moreover, the use of civil forfeiture bypasses some of the jurisdictional challenges that often stall international cybercrime cases. It allows U.S. law enforcement to act swiftly against assets, regardless of whether the criminals are apprehended. That puts real financial pressure on ransomware groups, potentially weakening their operational capacity.
The broader cybersecurity community should also take note. This case emphasizes the critical importance of cyber hygiene, incident response planning, and the value of working closely with federal agencies when breaches occur. Companies in Texas—and elsewhere—are likely breathing a sigh of relief knowing a threat actor tied to their region has been disrupted. But the temporary setback for Chaos doesn’t mean the threat is over. Like Hydra, cutting off one head often leads to another growing back unless the source is fully neutralized.
As the ransomware landscape continues to adapt, so too must defenders. Tools like blockchain intelligence, endpoint detection, and government-led cyber coalitions are proving invaluable. Yet, without consistent international policy alignment and a more proactive cybersecurity culture across enterprises, the ransomware threat will keep morphing, rebranding, and returning.
🔍 Fact Checker Results:
✅ The FBI did seize over 20 BTC from an address tied to Chaos ransomware
✅ The DOJ confirmed a civil forfeiture complaint on July 24, 2025
✅ Cybersecurity researchers link the new Chaos group to the BlackSuit operation
📊 Prediction:
Expect further law enforcement crackdowns on rebranded ransomware gangs like Chaos as digital forensics improve. Bitcoin traceability is becoming a crucial tool in tracking down criminals even when they shift tactics. Chaos and similar operations may respond with deeper anonymity layers, but the pressure is rising, and more seizures are likely in the coming months. 💣💻
References:
Reported By: www.bleepingcomputer.com
Extra Source Hub:
https://www.medium.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




