logo

msaRAT: Chaos Ransomware's New Backdoor Hides C2 Traffic Inside Chrome and Edge

ID: 715c171c-2314-51eb-a47a-b3fce6aab35c

STIX ID: report--715c171c-2314-51eb-a47a-b3fce6aab35c

Feed Name: CosmicBytez Labs

Threat Score
75/100

Date Published: 2026-07-23

Date Updated: 2026-07-24

...
...

Cisco Talos analyzed msaRAT, a Rust-based remote access trojan attributed to the Chaos ransomware group that avoids direct C2 connections by launching headless Chrome/Edge with remote debugging and tunneling commands over WebRTC (relayed via Twilio TURN and Cloudflare), making attacker traffic appear as normal browser activity; the report covers the infection chain (RMM-assisted deployment, MSI loading a DLL in memory), detection challenges, and network/endpoint defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.