Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process
ID: 80ab1468-82af-5196-bd1f-316b2878c45a
STIX ID: report--80ab1468-82af-5196-bd1f-316b2878c45a
Feed Name: Help Net Security
Cisco Talos describes msaRAT, a Rust-based remote access trojan attributed to the Chaos ransomware-as-a-service group that launches a headless Chrome/Edge instance, controls it via the Chrome DevTools Protocol, and tunnels C2 over WebRTC using Cloudflare Workers and Twilio TURN relays to hide the operator. Delivery uses an MSI masquerading as a Windows update, the RAT executes shell commands via cmd.exe and keeps its traffic loopback-local while the browser handles external TLS/STUN/WebRTC, and Talos has published indicators (delivery server, signaling domain, file hash) and a ClamAV signature for detection. The report emphasizes endpoint/host detection — spotting browsers started with remote debugging ports and custom user-data directories — as the most reliable detection point.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
