Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge
ID: 5a309b75-c2a4-59a3-8899-18b1c4eef592
STIX ID: report--5a309b75-c2a4-59a3-8899-18b1c4eef592
Feed Name: CosmicBytez Labs
Threat Score
**Executive summary:** Cisco Talos analyzed msaRAT, a Rust-based RAT used by the Chaos ransomware operation that routes its entire C2 through a victim's Chrome/Edge browser (via Chrome DevTools, Cloudflare Workers for signaling, and Twilio TURN relays) with double encryption, making network detection difficult; the report provides the attack chain, IOCs, detection and hunting guidance, a ClamAV signature, and notes that MuddyWater has attempted Chaos-branded false flags.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
