CHAOS — COMPLETE FEATURE LIST CORE REMOTE ACCESS Full Remote Desktop (HVNC) — Hidden Virtual Network Computing; operate the target system invisibly without the user knowing. Exclusive to Full tier.
Remote Shell — Full command-line access to the target system. Execute any command, script, or binary.
File Manager — Browse, upload, download, delete, and modify files on the target system. Unlimited file transfers.
👁️ SURVEILLANCE & MONITORING Live Keylogging — Capture every keystroke typed on the target system. Logs are saved and searchable via the C2 panel.
Webcam Capture — Take photos or record video from the target's webcam. Photo capture is available in Medium tier; Full tier includes real-time streaming.
Audio Recording — Capture microphone audio in real-time. Available exclusively in Full tier.
Screen Capture — Take screenshots of the target's active desktop at any time.
💰 DATA THEFT & EXFILTRATION Browser Credential Theft — Extract saved passwords, cookies, autofill data, and session tokens from all major browsers (Chrome, Firefox, Edge, Brave, Opera).
Discord Webhook Exfiltration — Automatically send stolen data to a Discord webhook URL. Available in all tiers (Lite includes this as primary feature).
Cryptocurrency Wallet Detection — Scan for and extract wallet files and credentials for 35+ browser extensions and 18+ standalone wallets (Full tier only).
Messenger Data Theft — Extract data from Discord, Telegram, and other messaging applications (Full tier only).
File Search & Exfil — Search for and exfiltrate files based on extension, name, or keywords (e.g., .docx, .pdf, .kdbx, .ovpn). 🛡️ PERSISTENCE & EVASION Multiple Persistence Methods — Registry Run keys, Scheduled Tasks, Startup folder, WMI, and COM hijacking.
DLL Sideloading — Load the Chaos client via legitimate Windows applications to avoid detection (Full tier only).
Process Injection — Inject Chaos into legitimate running processes (e.g., explorer.exe, svchost.exe).
AMSI/ETW Bypass — Disable Antimalware Scan Interface and Event Tracing