Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
ID: 848ce294-c4e9-5c2f-ae3b-fbe0282e06d9
STIX ID: report--848ce294-c4e9-5c2f-ae3b-fbe0282e06d9
Feed Name: Cisco Talos
### Executive summary Cisco Talos discovered and analyzed msaRAT, a sophisticated Rust-based remote access trojan used by the Chaos ransomware group that leverages Chrome DevTools Protocol and browser-executed WebRTC (signaled via Cloudflare Workers and relayed through Twilio TURN) to perform covert, double-encrypted C2 communications, enabling remote code execution and data exfiltration before ransomware deployment; the report contains infection chain details, IoCs, and detection signatures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
