logo

Chaos ransomware deploys browser-based msaRAT to evade network detection

ID: 016e6cc4-068b-54e3-b194-a1e5711e7cd8

STIX ID: report--016e6cc4-068b-54e3-b194-a1e5711e7cd8

Feed Name: Security Affairs

Threat Score
78/100

Date Published: 2026-07-23

Date Updated: 2026-07-23

Author: Pierluigi Paganini

...
...

Cisco Talos uncovered msaRAT, a Rust-based RAT used by the Chaos ransomware group that conceals C2 by routing all network traffic through the victim's Chrome/Edge browser via the Chrome DevTools Protocol and WebRTC; Cloudflare Workers is used for SDP signaling and Twilio for TURN relay so the attacker IP never appears on the wire. The RAT is delivered via a malicious MSI that loads a DLL into memory, runs headless browsers with remote debugging enabled, double-encrypts communications (ChaCha-Poly1305 over WebRTC/DTLS with ECDH key exchange), and is designed to evade traditional network monitoring—Talos provides IoCs and detection hints such as remote-debugging browser flags, HeadlessChrome user-agent strings, and specific installer behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.