logo

Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process

ID: 80ab1468-82af-5196-bd1f-316b2878c45a

STIX ID: report--80ab1468-82af-5196-bd1f-316b2878c45a

Feed Name: Help Net Security

Threat Score
78/100

Date Published: 2026-07-23

Date Updated: 2026-07-23

Author: Mirko Zorz

...
...

Cisco Talos describes msaRAT, a Rust-based remote access trojan attributed to the Chaos ransomware-as-a-service group that launches a headless Chrome/Edge instance, controls it via the Chrome DevTools Protocol, and tunnels C2 over WebRTC using Cloudflare Workers and Twilio TURN relays to hide the operator. Delivery uses an MSI masquerading as a Windows update, the RAT executes shell commands via cmd.exe and keeps its traffic loopback-local while the browser handles external TLS/STUN/WebRTC, and Talos has published indicators (delivery server, signaling domain, file hash) and a ClamAV signature for detection. The report emphasizes endpoint/host detection — spotting browsers started with remote debugging ports and custom user-data directories — as the most reliable detection point.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.