logo

Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge

ID: 5a309b75-c2a4-59a3-8899-18b1c4eef592

STIX ID: report--5a309b75-c2a4-59a3-8899-18b1c4eef592

Feed Name: CosmicBytez Labs

Threat Score
78/100

Date Published: 2026-07-26

Date Updated: 2026-07-27

...
...

**Executive summary:** Cisco Talos analyzed msaRAT, a Rust-based RAT used by the Chaos ransomware operation that routes its entire C2 through a victim's Chrome/Edge browser (via Chrome DevTools, Cloudflare Workers for signaling, and Twilio TURN relays) with double encryption, making network detection difficult; the report provides the attack chain, IOCs, detection and hunting guidance, a ClamAV signature, and notes that MuddyWater has attempted Chaos-branded false flags.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.