logo

Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel

ID: 848ce294-c4e9-5c2f-ae3b-fbe0282e06d9

STIX ID: report--848ce294-c4e9-5c2f-ae3b-fbe0282e06d9

Feed Name: Cisco Talos

Threat Score
80/100

Date Published: 2026-07-23

Date Updated: 2026-07-23

Author: Jordyn Dunk

...
...

### Executive summary Cisco Talos discovered and analyzed msaRAT, a sophisticated Rust-based remote access trojan used by the Chaos ransomware group that leverages Chrome DevTools Protocol and browser-executed WebRTC (signaled via Cloudflare Workers and relayed through Twilio TURN) to perform covert, double-encrypted C2 communications, enabling remote code execution and data exfiltration before ransomware deployment; the report contains infection chain details, IoCs, and detection signatures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.