Quick Summary
AllegedExecutive Summary
Chaos listed MS Walker on its dark web leak portal on August 25, 2026. This listing was identified through SOCRadar’s Dark Web Monitoring service. MS Walker is a professional services firm based in the United States, providing specialized consulting and related services across multiple industries. In the 60 days prior to this listing, Chaos claimed 15 other victims across Healthcare, Technology, and Professional Services, with geographic concentration in the United States, the United Kingdom, and East Asia. Recent listings with a comparable US professional-services profile include Tomorrow’s Office, Healthcare Highways, Neopharm Labs, and Wikoff Color Corporation. Chaos shows no strong sector exclusivity, moving between professional services and healthcare targets within the same campaign window.
Technical Analysis
SOCRadar’s stealer-log query for mswalker[.]com returned 15 records, 11 of which are employee credentials against corporate-owned infrastructure. High-value endpoints include five RDP/Terminal Server gateways (ts23, ts00, ts12, ts08, and ts67 subdomains of mswalker[.]com), RDP Web Access endpoints granting direct internal network access, and a corporate test and staging environment hosted on Vercel. One corporate username appeared across eight records spanning February through July 2026, indicating a lack of credential rotation over five months. The freshness window for these records is from May 22, 2024, to July 28, 2026. Employee credentials on RDP gateways and RDWeb endpoints represent infrastructure commonly used by ransomware operators for lateral movement. The two-year freshness span, coupled with a single unrotated username appearing multiple times, suggests a persistent access window that has remained open for an extended period, potentially exceeding typical ransomware dwell-time benchmarks. While these specific credentials have not been confirmed as the entry point used by Chaos, the profile aligns with access often acquired through initial access brokers and pre-deployment staging activities. Next Steps: Rotate credentials for all accounts identified in the stealer-log records immediately, prioritizing the username that appeared across eight records. Audit RDP gateway and RDWeb access logs from May 2024 onward for anomalous sessions. Restrict or disable external RDP access where internal alternatives exist, and review the Vercel staging environment for sensitive data exposure.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.