msaRAT: Chaos Ransomware's New Backdoor Hides C2 Traffic Inside Chrome and Edge
ID: 715c171c-2314-51eb-a47a-b3fce6aab35c
STIX ID: report--715c171c-2314-51eb-a47a-b3fce6aab35c
Feed Name: CosmicBytez Labs
Cisco Talos analyzed msaRAT, a Rust-based remote access trojan attributed to the Chaos ransomware group that avoids direct C2 connections by launching headless Chrome/Edge with remote debugging and tunneling commands over WebRTC (relayed via Twilio TURN and Cloudflare), making attacker traffic appear as normal browser activity; the report covers the infection chain (RMM-assisted deployment, MSI loading a DLL in memory), detection challenges, and network/endpoint defensive recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
