logo

New msaRAT malware uses Chrome, Edge browsers to route C2 traffic

ID: 3758c65b-1f46-53cd-99ec-670a2e6e4be2

STIX ID: report--3758c65b-1f46-53cd-99ec-670a2e6e4be2

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-07-23

Date Updated: 2026-07-23

Author: Bill Toulas

...
...

The report details msaRAT, a Rust backdoor deployed by the Chaos ransomware group that establishes C2 via Chrome/Edge headless sessions controlled through the Chrome DevTools Protocol; it uses Cloudflare Workers for signaling and Twilio TURN relays to conceal the attacker infrastructure, implements dual-layer encryption (WebRTC DTLS and ChaCha20-Poly1305 + ECDH), and has been observed in phishing-driven intrusions where a malicious MSI loads the backdoor in memory.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.